UP UPI PayInfrastructure
Trust centre

Security at UPI Pay

Our controls are designed to protect merchant separation, API access and the integrity of payment-status events.

Platform controls

  • HTTPS transport for browser and API traffic.
  • Hashed customer API keys and encrypted provider credentials.
  • CSRF protection, authenticated dashboards and rate-limited sensitive endpoints.
  • Signed webhooks so merchants can validate event authenticity.
  • Server-side payment verification before an order is treated as paid.
  • Application logs and database backups for operational recovery.

Shared responsibility

Customers must protect passwords and API keys, restrict production access, verify webhook signatures, use unique order references and never place secret keys in browser or mobile-app code. UPI PINs and banking OTPs must never be entered into UPI Pay.

Report a concern

Email support@upipay.fun with a description and reproducible steps. Do not include live passwords, API secrets or personal financial credentials.