Security

Payments only work when they are trusted. Here is how MittoPay protects merchant funds, customer data, and the platform itself.

Effective September 10, 2026Questions: contact@mittopay.com

Our approach

MittoPay is built on the assumption that every layer will one day be attacked. We limit what any single component can see or do, monitor continuously, and rehearse incidents before they happen. Security controls apply equally to production and to the sandbox, so the environment you integrate against behaves like the one that moves real money.

Encryption everywhere

TLS 1.2+ for all traffic, AES-256 at rest, and field-level encryption for account identifiers and credentials.

Least privilege

Role-based access for staff and merchants, hardware-key MFA for production, and short-lived credentials.

Continuous monitoring

Centralised logging, anomaly detection on API traffic, and a risk engine scoring every transaction in real time.

Independent testing

Third-party penetration testing before launch and at least annually, ongoing automated scanning, and a responsible-disclosure programme.

Data protection

Card data never touches merchant servers when you use hosted checkout; it is captured in a PCI DSS compliant environment operated with our acquiring partners. Bank account and wallet identifiers are tokenised, and raw values are encrypted and accessible only to the settlement service.

Production data is segregated from sandbox and development. Backups are encrypted, stored in a separate region, and restore-tested on a scheduled basis.

API and integration security

  • Requests are authenticated with per-environment secret keys; keys can be rotated instantly from the dashboard and are never shown again after creation.
  • Every webhook is signed with an HMAC signature and a timestamp so you can verify origin and reject replays.
  • Idempotency keys prevent duplicate collections or payouts if a request is retried.
  • IP allow-listing and rate limiting are available per key.
  • The sandbox mirrors production behaviour, including error codes and webhook timing, so edge cases are found before go-live.

Fraud and financial-crime controls

Our adaptive risk engine scores each transaction using device, velocity, behavioural, and corridor-specific signals, and can hold, step-up, or decline in real time. Merchants and their beneficial owners are verified at onboarding and screened continuously against Canadian and international sanctions lists and PEP lists. Funds move only between accounts and wallets verified in the customer's own name; we do not support peer-to-peer trading, cash, or anonymous occasional transactions. Suspicious activity is reviewed by a dedicated compliance team and reported where the law requires.

Availability and resilience

The platform runs across multiple availability zones with automated failover. Payment routing is dynamic: if a partner rail degrades, traffic shifts to an alternative path without merchant action. We target 99.9% monthly uptime for the API; any contractual service levels are set out in your order form. Incidents and maintenance windows are communicated to merchants by email and in the dashboard.

Incident response

A 24/7 on-call rotation owns security and availability incidents. We follow a documented runbook covering containment, forensics, customer communication, and post-incident review. Merchants affected by a security incident are notified without undue delay, with a clear description of impact and the steps we are taking.

Compliance

MittoPay is operated by Virentis Payment Corporation, a Canadian company (British Columbia Incorporation No. BC1592848) that is a money services business under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and subject to FINTRAC's registration, record-keeping, and reporting requirements. We maintain a documented AML/CFT Compliance Program covering customer due diligence, ongoing monitoring, sanctions screening, record keeping, and suspicious-transaction reporting, reviewed independently at least every two years as the law requires.

Our technical controls are designed in line with recognised frameworks including PCI DSS, ISO/IEC 27001, and SOC 2. Independent attestations and audit reports are shared with merchants under NDA as they are obtained, together with a summary of our compliance program.

Responsible disclosure

If you believe you have found a vulnerability in a MittoPay system, please email contact@mittopay.com with the subject line "Security report". Include enough detail for us to reproduce the issue. We will acknowledge within two business days, keep you informed of progress, and will not pursue legal action against good-faith research that avoids privacy violations, data destruction, and service disruption.