Security
What OneGate protects, stores and never touches.
Card data
OneGate never collects card numbers, CVV or card PINs. Card entry happens on your acquiring bank's hosted page; OneGate receives only the payment result and references.
Secrets
Provider credentials, webhook secrets and two-factor seeds are envelope-encrypted (AES-GCM data keys; key-encryption keys in AWS KMS in production), bound to their owner record, and never returned by the API or written to logs. API secret keys are stored only as SHA-256 hashes.
Accounts
Passwords use Argon2id. Sessions are host-only, Secure, HttpOnly cookies with an inactivity timeout; TOTP two-factor authentication is available and required for OneGate staff. Team access uses roles (Owner, Admin, Developer, Finance, Support, Viewer) enforced by the API.
Integrity
Payment timelines, events, audit logs and the billing ledger are append-only. Every state change passes a strict state machine inside a database transaction.
Your side
Verify webhook signatures, keep keys server-side, and use HTTPS return URLs. See the go-live checklist.
Reporting vulnerabilities
Email info@onegate.am with the subject “Security report”.