Security at Cryptomo
How we protect merchant accounts, API access and customer payments.
Payments are only as trustworthy as the systems behind them. This page explains the controls built into Cryptomo and what you can do to keep your account safe.
Account protection
- Two-factor authentication (2FA). Protect your login with an authenticator app (Google Authenticator, Authy, 1Password and others). Recovery codes let you get back in if you lose your phone. 2FA is required for administrators.
- Strong passwords. Passwords are stored as one-way hashes; we can never see them.
- Sign-in alerts. We email you when your account is accessed from a new IP address.
- Brute-force protection. Repeated failed logins are rate-limited and temporarily locked, and public forms are protected against bots with Cloudflare Turnstile.
- Team roles. Give staff their own login with a limited role (manager, finance, developer or viewer) instead of sharing your password.
API and integration security
- Signed API requests. Every API call is signed with HMAC-SHA256 over the timestamp, method, path and body. A stolen request cannot be replayed or changed.
- Signed webhooks. Every notification to your store carries an HMAC signature and a timestamp, so your server can reject forged or replayed messages. See how to verify webhooks.
- Scoped keys. API keys can be read-only and limited to specific IP addresses. Secret keys are shown only once.
- Idempotency. Retried requests with the same idempotency key never create duplicate invoices.
Protecting your funds
- Own-wallet payments. On Pro and Business, customer payments go straight to wallets you control. We never hold those funds.
- Withdrawal address locks. New payout addresses can be locked for a waiting period, and you are notified by email whenever one is added.
- Address verification. Every address is validated for its network before it is used.
- We never store private keys for merchant wallets. Only public addresses and extended public keys (xpubs) are used to receive payments.
Data protection
- Encryption in transit. All traffic uses HTTPS with HSTS.
- Encryption at rest. API secrets, webhook secrets and third-party credentials are encrypted in our database. Identity documents uploaded for verification are encrypted and accessible only to authorised staff.
- Audit log. Sensitive account changes are recorded so they can be reviewed.
- Backups. The database is backed up daily.
- Strict browser security. A content security policy, frame protection and secure cookies reduce the risk of cross-site attacks.
Compliance
We follow an AML/CTF and KYC policy and an Acceptable Use Policy to keep criminals off the platform. Read how we handle personal information in our Privacy Policy.
What you can do
- Turn on 2FA in Account → Security
- Keep API secrets and webhook secrets out of code repositories and front-end code
- Always verify webhook signatures before marking orders paid
- Restrict API keys to your server's IP address
- Use own-wallet payments and a hardware wallet for long-term storage
Report a vulnerability
Found a security issue? Please tell us privately through the contact form with the subject "Security". We investigate every report and will not take action against good-faith research that avoids harm to users and data.
ابدأ بقبول العملات المشفّرة اليوم
ابدأ مجانًا. 1% لكل دفعة. قم بالترقية في أي وقت.
أنشئ حسابك المجاني