Nexpay
Security

Security is the foundation, not a feature.

Nexpay is built with security decisions baked into every layer — from how sessions work, to how transactions are recorded, to how API access is scoped.

How Nexpay protects your account and money.

Concrete measures we take across accounts, transactions, data, and API access.

Account security

Passwords are hashed with strong algorithms. Sessions use secure cookies, are regenerated periodically, and are protected against fixation.

Transaction security

All financial operations run server-side. Balances are computed from a double-entry ledger — no client-side math is trusted.

Identity verification (KYC)

When cumulative activity reaches the platform threshold, users complete verification before specific actions become available.

Transaction monitoring

Every financial event is recorded with a unique reference. Activity can be reviewed by our operations team when needed.

API security

API access uses scoped keys with separate sandbox and live environments, rate limiting, and webhook signature verification.

Audit trails

Administrative and security-sensitive actions are logged with actor, timestamp, and context.

Your responsibilities

Security is a shared responsibility. Nexpay protects the platform; you protect your account.

  • Never share your password or verification codes with anyone.
  • Use a unique password for your Nexpay account.
  • Keep your email account secure — it's the recovery path for Nexpay.
  • Review your transaction history regularly.
  • Contact us immediately if you suspect unusual activity.
Responsible disclosure

Found a security issue?

If you believe you've identified a security issue with Nexpay, please contact us privately so we can investigate and address it.

Please do not publicly disclose the issue before we've had a chance to respond.

support@nexbyt.com