Security
Security built into every payment flow
CentraPoint sits between your customers, your gateways and your books. These are the controls we use to keep that flow trustworthy.
Credentials encrypted at rest
Gateway credentials (merchant IDs, keys and secrets) are encrypted at rest using AES-256-GCM, an authenticated encryption mode that also detects tampering.
Webhook verification
Inbound gateway notifications are checked against the provider's signature scheme. Where the gateway supports it, CentraPoint then re-verifies the transaction server-side with the gateway before marking a payment as paid.
Tamper-proof payment links
Payment links are HMAC-signed. Changing the amount, reference or any signed field invalidates the link.
Role-based access
Users are assigned admin, staff or viewer roles so that sensitive actions are limited to the right people.
Audit and webhook logs
An audit log records user actions and a webhook log records gateway notifications, supporting investigations and reconciliation.
API key management
API keys can be issued and revoked from the dashboard, so integrations can be rotated or cut off quickly.
Card data stays with your gateway
Customers enter card and banking details on your gateway's hosted pages. CentraPoint works with payment references, statuses and amounts rather than storing full card numbers.
Privacy and POPIA
We process personal information in line with South Africa's Protection of Personal Information Act (POPIA). See our privacy policy for details.
Reporting a security issue
If you believe you have found a vulnerability, please contact us with the subject "Security". Please do not publicly disclose the issue until we have had a chance to investigate.
Ready to simplify how you get paid?
Create your CentraPoint account, connect the gateways you already use, and start sending payment links and invoices.