Controls before claims
Protect the payment decision from checkout to reconciliation
EPS treats security as an operating model: protect credentials, verify server events, separate environments, keep evidence, and review business eligibility before production activation.
Formal certifications, regulatory status, scheme access, and method eligibility must be confirmed in the merchant offer and applicable service documentation.
The merchant and gateway each own part of the boundary
Security depends on both the EPS environment and the merchant implementation. Production access should document who stores credentials, who validates events, and who can change payment or refund settings.
- 1Encrypted transport
HTTPS for checkout creation, browser return, status requests, callbacks, and merchant access.
- 2Signed events
Integrity checks before a callback can change an order or trigger fulfillment.
- 3Credential boundaries
Separate test and live secrets, limit access, and rotate when exposure is suspected.
- 4Event evidence
Keep order, gateway, status, timestamp, refund, and settlement references together.
A secure gateway cannot fix an unsafe merchant implementation
Production readiness includes the merchant website, server code, staff permissions, products, fulfillment, refund workflow, and incident contact route.
| Control area | EPS service boundary | Merchant responsibility |
|---|---|---|
| Credentials | Issue and validate the applicable integration credentials. | Store secrets outside public code and restrict staff or system access. |
| Payment status | Return the transaction state available to the integration. | Verify the event and amount before fulfillment or account activation. |
| Customer data | Limit data collection to what the payment flow requires. | Protect customer and order data in the merchant system and privacy process. |
| Refunds | Expose the approved refund workflow and resulting transaction state. | Control staff permissions, customer policy, and refund evidence. |
| Incidents | Maintain an escalation route for gateway-side events. | Detect website, credential, order, or staff-account compromise and escalate promptly. |
Confirm the evidence, not just the label
Before relying on a certification, license, payment method, or partner statement, request the current scope and applicability for the exact merchant service.
- Entity and service covered by the evidence
- Current validity period and scope
- Merchant responsibilities or exclusions
- Payment methods, regions, and integration routes included
- Incident, dispute, and complaint escalation path