Cartflox, home
Security

Security

Last updated: July 2026.

1. Security architecture

Cartflox designed its infrastructure on the principle of security by design:

• Multi-layer architecture with demilitarised zones (DMZ)
• Web application firewalls (WAF) on all exposed interfaces
• Strict network isolation between critical components
• Least-privilege principle for all internal access
• Immutable logging of all sensitive operations
• Daily encrypted backups with monthly restore tests

2. API key security

Your Cartflox API keys are sensitive credentials. We recommend that you:

• Never expose your secret key in frontend or public code
• Use environment variables to store your keys
• Regenerate your keys immediately if you suspect they have been compromised
• Use different keys for your test and production environments
• Restrict each key's permissions to the strict minimum (read-only, write, etc.)

You can regenerate or revoke your keys at any time from your dashboard.

3. Fraud prevention

Cartflox includes a real-time fraud prevention engine:

• Risk scoring based on transaction behaviour
• Detection of abnormal patterns (unusual amounts, high frequency, geolocation)
• Automatic blocking of suspicious IP addresses
• Blocklists shared between merchants (anonymised)
• Mobile money numbers checked against known fraud databases
• Real-time alerts to merchants in the event of a suspicious attempt

4. Incident management

In the event of a security incident, our procedure is as follows:

• Incident detected and classified within 1 hour
• Affected systems isolated within 2 hours
• Affected merchants notified within 24 hours
• Preliminary incident report within 72 hours
• Full incident report within 7 days
• Corrective measures and post-mortem shared

In the event of a personal data breach, we notify the competent authorities and the individuals concerned within the regulatory deadlines.

5. Reporting a vulnerability

Cartflox encourages the responsible disclosure of security vulnerabilities.

If you discover a flaw, contact us via https://cartflox.com/en/contact (subject: [SECURITY])

We undertake to:
• Acknowledge receipt within 24 hours
• Confirm the vulnerability within 5 business days
• Keep you informed of progress on the fix
• Not take legal action over a disclosure made in good faith

We reward significant findings according to their severity (Bug Bounty programme).

6. Best practices for merchants

To maximise the security of your Cartflox integration:

• Always verify webhook signatures with your secret key
• Use HTTPS for all your callback endpoints
• Validate amounts and references server-side before confirming an order
• Implement idempotency logic to avoid double processing
• Limit payment attempts per session
• Log all transactions on your side of the system