Անցնել բովանդակությանը
OneGate փաստաթղթեր
Կառավարման վահանակ
Ուղեցույցներ

Այս էջը հասանելի է միայն անգլերենով։ Կոդը, API դաշտերը և նույնացուցիչները չեն թարգմանվում։

Security

What OneGate protects, stores and never touches.

Card data

OneGate never collects card numbers, CVV or card PINs. Card entry happens on your acquiring bank's hosted page; OneGate receives only the payment result and references.

Secrets

Provider credentials, webhook secrets and two-factor seeds are envelope-encrypted (AES-GCM data keys; key-encryption keys in AWS KMS in production), bound to their owner record, and never returned by the API or written to logs. API secret keys are stored only as SHA-256 hashes.

Accounts

Passwords use Argon2id. Sessions are host-only, Secure, HttpOnly cookies with an inactivity timeout; TOTP two-factor authentication is available and required for OneGate staff. Team access uses roles (Owner, Admin, Developer, Finance, Support, Viewer) enforced by the API.

Integrity

Payment timelines, events, audit logs and the billing ledger are append-only. Every state change passes a strict state machine inside a database transaction.

Your side

Verify webhook signatures, keep keys server-side, and use HTTPS return URLs. See the go-live checklist.

Reporting vulnerabilities

Email info@onegate.am with the subject “Security report”.