Account security
Passwords are hashed with strong algorithms. Sessions use secure cookies, are regenerated periodically, and are protected against fixation.
Nexpay is built with security decisions baked into every layer — from how sessions work, to how transactions are recorded, to how API access is scoped.
Concrete measures we take across accounts, transactions, data, and API access.
Passwords are hashed with strong algorithms. Sessions use secure cookies, are regenerated periodically, and are protected against fixation.
All financial operations run server-side. Balances are computed from a double-entry ledger — no client-side math is trusted.
When cumulative activity reaches the platform threshold, users complete verification before specific actions become available.
Every financial event is recorded with a unique reference. Activity can be reviewed by our operations team when needed.
API access uses scoped keys with separate sandbox and live environments, rate limiting, and webhook signature verification.
Administrative and security-sensitive actions are logged with actor, timestamp, and context.
Security is a shared responsibility. Nexpay protects the platform; you protect your account.
If you believe you've identified a security issue with Nexpay, please contact us privately so we can investigate and address it.
Please do not publicly disclose the issue before we've had a chance to respond.
support@nexbyt.com