Security Architecture & Compliance
TezVerify's security model is designed from the ground up to eliminate single points of failure, isolate tenant secrets with envelope encryption, and enforce zero custody over merchant financial balances.
Envelope Encryption
AES-256-CBC with tenant-isolated salts for Google App Passwords and secret keys.
Zero Custody P2P
Funds move directly between buyer and seller mobile wallets. Zero financial pooling.
Idempotent Engine
Transaction ID (TID) deduplication prevents replay attacks and double claims.
Envelope Encryption Architecture
All sensitive merchant credentials (specifically 16-character Google App Passwords and API keys) are encrypted using AES-256-CBC envelope encryption. Plaintext passwords never touch database storage or log files.
Zero-Custody Money Flow
Unlike traditional payment gateways that hold rolling reserves or charge high percentage commissions, TezVerify operates exclusively as a verification telemetry layer.
- No Wallet Custody: TezVerify never collects, holds, or routes customer money. Funds travel directly from the buyer's Easypaisa/JazzCash wallet to your mobile account.
- No Account Credentials Required: We never ask for your banking PINs, login passwords, or OTPs.
- Zero Rolling Reserves: 100% of customer payments land directly in your own account in real-time.
IMAP Scope & Strict Data Minimization
When connecting a Gmail inbox via Google App Password, our automated workers execute targeted IMAP queries restricted exclusively to financial alert notifications.
Targeted Senders Only: Workers search only for messages originating from 3737 (Easypaisa), 8558 (JazzCash), or recognized commercial bank SMS gateways.
Zero Email Storage: Email bodies are parsed in memory to extract the Transaction ID (TID) and amount, then immediately discarded. No email text or personal correspondence is saved.
Webhook Integrity & Signature Verification
Outbound webhooks sent to your storefront (Shopify, WooCommerce, custom PHP) are signed with HMAC-SHA256 signatures using your merchant webhook secret.
Every webhook payload includes timestamp headers to prevent replay attacks, ensuring your backend processes callbacks securely.