WHITCOMB PAYMENTS← BACK TO SITE
TRUST

Security at Whitcomb

How we protect card data, merchant accounts, and the integrity of what we ship. Plain statements, no badges — everything on this page describes how the platform actually works.

Card data never touches our servers

When a customer pays, card details are entered on a hosted payment page operated by our PCI-certified processing partner. The card number, expiry, and security code go directly from the customer’s browser to that partner’s certified infrastructure — they are never transmitted to, processed by, or stored on Whitcomb systems. What Whitcomb keeps is the order record: reference, amount, and payment status.

Store connections are signed, not password-based

A merchant’s store authenticates every report and checkout request with a cryptographic signature over the request body, keyed on a store secret issued at activation. Requests without a valid signature are refused before anything is read. Merchants never handle raw API keys, and there is no shared password to leak.

Payment notifications are verified

Incoming payment-status notifications from our processing partner carry HMAC signatures that we verify against a shared signing secret, with timestamp checks against replay, before any record is updated. An unsigned or mis-signed notification changes nothing.

Deployments are integrity-pinned

Every production deployment verifies a cryptographic hash of every file in the release before it ships. If a single file differs from what was reviewed, the build refuses and production keeps the previous release.

Transport and platform

Data we hold, and don’t

We hold merchant business records — applications, contact details, order and settlement records — for as long as the relationship and law require. We do not hold customer card numbers, and we do not sell data. Our Privacy Policy covers the details.

Reporting a vulnerability

If you believe you have found a security issue anywhere on whitcombpayments.com, chat with us now and open with chat with us now and open with “Security report”.ldquo;Security reportchat with us now and open with “Security report” in the subject.rdquo;. Include enough detail to reproduce. We read every report, we will acknowledge yours, and we ask that you give us a reasonable window to fix before public disclosure. Good-faith research conducted without harming merchants, customers, or service availability will not be met with legal action. A machine-readable contact lives at /.well-known/security.txt.

Questions from a merchant’s bank, auditor, or platform reviewer? Chat with us now and we’ll answer directly.