Security at OneGate
OneGate sits between your systems and your payment providers. This page explains, factually, how payments flow, what we store, what we never store and how we protect it. We do not use vague “bank-grade” claims.
How payments flow
Your server creates a payment with the OneGate API. The customer opens OneGate's hosted checkout, chooses a method and is sent to the provider's own page (for example, your acquiring bank's card page or the wallet's page) to authorise the payment. The provider settles the money to your account under your contract with it. OneGate records the result, confirms it with the provider where the provider supports status checks, and sends you a signed webhook.
OneGate is non-custodial: it never holds, pools or pays out merchant or customer funds.
What OneGate stores
To run the service, OneGate stores the operational data it needs:
- Account data: your team members' names, email addresses and security settings.
- Organisation and business-verification details you submit before going live.
- Payment records: amount, currency, your order ID and description, the metadata you send, status history and provider references.
- Events, webhook deliveries and refunds.
- Redacted API request logs and an audit log of security-relevant actions.
- Sanitised provider diagnostics, kept for 30 days by default (this period is under compliance review).
- The provider credentials you configure, encrypted (see below).
What OneGate never stores
- Card numbers (PAN), CVV/CVC codes or card PINs.
- Your customers' bank, wallet or Idram/Telcell passwords.
- Customer or merchant funds.
- Cryptocurrency private keys or seed phrases.
- Your API secret keys in readable form (only a one-way hash).
Card-data boundary
Card details are entered only on your acquiring bank's hosted payment page. OneGate's checkout has no card fields, and card data never passes through OneGate's servers. OneGate receives the payment result and provider references, never the card number.
Provider credentials
Credentials such as merchant IDs, secret keys and passwords for your providers are encrypted before they are stored, using envelope encryption (AES-GCM). In production the key-encryption keys are managed by AWS Key Management Service. After you save a secret, the dashboard never shows it again; you can only replace it.
API keys
Secret API keys are shown once, when you create them. OneGate stores only a SHA-256 hash and compares keys in constant time. Keys are separate for Test and Live, can be limited with scopes, and can be revoked at any time. Live keys require a verified email address.
Webhook signing
Every webhook is signed with HMAC-SHA256 over its timestamp and raw body. Verify the signature and reject timestamps older than five minutes to block replays. When you rotate a signing secret, the previous secret keeps working for 24 hours so you can deploy without downtime. The official SDKs implement this verification.
Account and session security
Passwords are hashed with Argon2id. You can turn on two-factor authentication with an authenticator app, see your active sessions and sign them out. Dashboard sessions use secure, HttpOnly cookies limited to the dashboard's own domain, and expire after inactivity. OneGate staff must use two-factor authentication, and every staff action that affects merchants is recorded in an audit log.
Test and Live isolation
Test and Live use separate API keys, separate provider connections and separate data. Test payments go to the OneGate Sandbox or to a provider's test environment and never move real money. Live processing requires business verification, and each real provider is enabled only after OneGate's integration with it has been certified. Every organisation's data is isolated: a key or session of one organisation cannot read or change another's.
Infrastructure
OneGate runs on Amazon Web Services. In production, traffic is served over HTTPS with TLS 1.2 or newer and HTTP Strict Transport Security. The database, queues, file storage and backups are encrypted at rest, and the database is reachable only from OneGate's private network. The database is backed up automatically with point-in-time recovery.
Logging and redaction
Before request logs, provider diagnostics, audit records and error reports are stored, OneGate removes secrets such as passwords, API keys, signatures and tokens, and masks anything that looks like a card number. Error reports never include request bodies or customer data.
Certifications
OneGate does not currently hold PCI DSS, SOC 2 or ISO 27001 certification, and we do not claim otherwise. Because card data is entered only on your acquirer's page, it never reaches OneGate's systems; your acquirer can confirm your own PCI obligations.
Reporting a security issue
If you believe you have found a vulnerability, email info@onegate.am with the subject “Security report”. Describe the issue and how to reproduce it. Please do not access data that is not yours, do not degrade the service, and give us reasonable time to fix the issue before disclosing it. We will acknowledge your report and keep you updated.
Email a security reportThis page describes the service as implemented; it is reviewed whenever the security design changes.