Security
Last updated: July 2026.
1. Security architecture
Cartflox designed its infrastructure on the principle of security by design:
• Multi-layer architecture with demilitarised zones (DMZ)
• Web application firewalls (WAF) on all exposed interfaces
• Strict network isolation between critical components
• Least-privilege principle for all internal access
• Immutable logging of all sensitive operations
• Daily encrypted backups with monthly restore tests
2. API key security
Your Cartflox API keys are sensitive credentials. We recommend that you:
• Never expose your secret key in frontend or public code
• Use environment variables to store your keys
• Regenerate your keys immediately if you suspect they have been compromised
• Use different keys for your test and production environments
• Restrict each key's permissions to the strict minimum (read-only, write, etc.)
You can regenerate or revoke your keys at any time from your dashboard.
3. Fraud prevention
Cartflox includes a real-time fraud prevention engine:
• Risk scoring based on transaction behaviour
• Detection of abnormal patterns (unusual amounts, high frequency, geolocation)
• Automatic blocking of suspicious IP addresses
• Blocklists shared between merchants (anonymised)
• Mobile money numbers checked against known fraud databases
• Real-time alerts to merchants in the event of a suspicious attempt
4. Incident management
In the event of a security incident, our procedure is as follows:
• Incident detected and classified within 1 hour
• Affected systems isolated within 2 hours
• Affected merchants notified within 24 hours
• Preliminary incident report within 72 hours
• Full incident report within 7 days
• Corrective measures and post-mortem shared
In the event of a personal data breach, we notify the competent authorities and the individuals concerned within the regulatory deadlines.
5. Reporting a vulnerability
Cartflox encourages the responsible disclosure of security vulnerabilities.
If you discover a flaw, contact us via https://cartflox.com/en/contact (subject: [SECURITY])
We undertake to:
• Acknowledge receipt within 24 hours
• Confirm the vulnerability within 5 business days
• Keep you informed of progress on the fix
• Not take legal action over a disclosure made in good faith
We reward significant findings according to their severity (Bug Bounty programme).
6. Best practices for merchants
To maximise the security of your Cartflox integration:
• Always verify webhook signatures with your secret key
• Use HTTPS for all your callback endpoints
• Validate amounts and references server-side before confirming an order
• Implement idempotency logic to avoid double processing
• Limit payment attempts per session
• Log all transactions on your side of the system