Encrypted in transit
All traffic is served over TLS with modern cipher suites and HSTS. Plain-text HTTP requests are redirected before any credential is accepted.
Security
Money movement raises the stakes on every part of the stack. This page describes the controls behind AxPay sign-in, the settings you control yourself, and how to reach us if you find a problem.
Defaults that apply to every account, with no configuration required.
All traffic is served over TLS with modern cipher suites and HSTS. Plain-text HTTP requests are redirected before any credential is accepted.
Stored data is encrypted at rest. Passwords are never stored in a recoverable form — only a salted hash from a slow, memory-hard function.
Time-based one-time codes and passkeys are supported on every plan. Administrators can require a second factor for all members of an organisation.
Sign-ins, permission changes, and payment-setting edits are written to an audit trail that administrators can review and export.
Roles separate viewing, initiating, and approving a payment, so no single account holds every permission by default.
Automated checks watch for credential stuffing, impossible-travel sign-ins, and unusual payment patterns, and raise alerts on the account.
Available in account settings once you are signed in.
A password manager plus a password used nowhere else removes the most common cause of account takeover: reuse of a password leaked from another site.
Sign in only from a page served on our own domain. We never ask for your password or a verification code by email, chat, or phone.
An out-of-date recovery email or a lost set of recovery codes turns a small problem into a long one. Review them when your team changes.
We welcome reports from security researchers and will not pursue legal action for good-faith research that respects the guidelines below.
Send reports to the security contact listed on our support page. We acknowledge reports within three business days and keep you updated until the issue is resolved.
No. Nobody from AxPay will ask for your password or a one-time code. Treat any such request as an attempted fraud and report it.
Attempts are rate-limited and the account is temporarily locked. You keep access through password reset and your second factor.
Yes. Alerts for a new device or location are on by default and can be delivered by email or push notification.