Card data never touches our servers
When a customer pays, card details are entered on a hosted payment page operated by our PCI-certified processing partner. The card number, expiry, and security code go directly from the customer’s browser to that partner’s certified infrastructure — they are never transmitted to, processed by, or stored on Whitcomb systems. What Whitcomb keeps is the order record: reference, amount, and payment status.
Store connections are signed, not password-based
A merchant’s store authenticates every report and checkout request with a cryptographic signature over the request body, keyed on a store secret issued at activation. Requests without a valid signature are refused before anything is read. Merchants never handle raw API keys, and there is no shared password to leak.
Payment notifications are verified
Incoming payment-status notifications from our processing partner carry HMAC signatures that we verify against a shared signing secret, with timestamp checks against replay, before any record is updated. An unsigned or mis-signed notification changes nothing.
Deployments are integrity-pinned
Every production deployment verifies a cryptographic hash of every file in the release before it ships. If a single file differs from what was reviewed, the build refuses and production keeps the previous release.
Transport and platform
- All traffic is encrypted in transit (TLS, HSTS with preload).
- Content-Security-Policy, frame-ancestors, and referrer restrictions on every page.
- Databases are encrypted at rest by our infrastructure providers and reachable only over authenticated, encrypted connections.
- Staff areas sit behind authenticated, expiring session tokens; sensitive desk actions additionally require a separate PIN.
Data we hold, and don’t
We hold merchant business records — applications, contact details, order and settlement records — for as long as the relationship and law require. We do not hold customer card numbers, and we do not sell data. Our Privacy Policy covers the details.
Reporting a vulnerability
If you believe you have found a security issue anywhere on whitcombpayments.com, chat with us now and open with chat with us now and open with “Security report”.ldquo;Security reportchat with us now and open with “Security report” in the subject.rdquo;. Include enough detail to reproduce. We read every report, we will acknowledge yours, and we ask that you give us a reasonable window to fix before public disclosure. Good-faith research conducted without harming merchants, customers, or service availability will not be met with legal action. A machine-readable contact lives at /.well-known/security.txt.