SECURITY BY DESIGN

BHOLAPAY Security Model

Credential protection

Connector passwords, API secrets and webhook secrets are encrypted at rest. Merchant API requests use signed payloads.

Private proof storage

Payment screenshots are kept outside the public asset path and served only through authenticated review routes.

Merchant isolation

Merchant queries are scoped by merchant ID so one merchant cannot access another merchant's payments or reports.

Auditability

Administrative actions and operational events can be recorded in the audit log for investigation and reconciliation control.