Security

Protecting your account and your payments

Money movement raises the stakes on every part of the stack. This page describes the controls behind AxPay sign-in, the settings you control yourself, and how to reach us if you find a problem.

Platform controls

Defaults that apply to every account, with no configuration required.

Encrypted in transit

All traffic is served over TLS with modern cipher suites and HSTS. Plain-text HTTP requests are redirected before any credential is accepted.

Encrypted at rest

Stored data is encrypted at rest. Passwords are never stored in a recoverable form — only a salted hash from a slow, memory-hard function.

Multi-factor authentication

Time-based one-time codes and passkeys are supported on every plan. Administrators can require a second factor for all members of an organisation.

Auditable access

Sign-ins, permission changes, and payment-setting edits are written to an audit trail that administrators can review and export.

Least-privilege roles

Roles separate viewing, initiating, and approving a payment, so no single account holds every permission by default.

Monitoring and alerts

Automated checks watch for credential stuffing, impossible-travel sign-ins, and unusual payment patterns, and raise alerts on the account.

Settings you control

Available in account settings once you are signed in.

  • Turn on two-step verification and register a passkey
  • Review active sessions and revoke any device
  • Generate and rotate single-use recovery codes
  • Choose email or push alerts for new sign-ins
  • Set approval thresholds so large payments need a second person
  • Restrict access to named IP ranges

Habits that help

Use a unique password

A password manager plus a password used nowhere else removes the most common cause of account takeover: reuse of a password leaked from another site.

Check the address bar

Sign in only from a page served on our own domain. We never ask for your password or a verification code by email, chat, or phone.

Keep recovery options current

An out-of-date recovery email or a lost set of recovery codes turns a small problem into a long one. Review them when your team changes.

Reporting a vulnerability

We welcome reports from security researchers and will not pursue legal action for good-faith research that respects the guidelines below.

  • Test only against your own account and data.
  • Do not run denial-of-service tests, spam, or social engineering against our staff or users.
  • Give us reasonable time to ship a fix before publishing details.
  • Include clear reproduction steps and the impact you observed.

Send reports to the security contact listed on our support page. We acknowledge reports within three business days and keep you updated until the issue is resolved.

Security FAQ

Will AxPay ever ask for my password?

No. Nobody from AxPay will ask for your password or a one-time code. Treat any such request as an attempted fraud and report it.

What happens after several failed sign-ins?

Attempts are rate-limited and the account is temporarily locked. You keep access through password reset and your second factor.

Can I be told about new sign-ins?

Yes. Alerts for a new device or location are on by default and can be delivered by email or push notification.