Our Security Approach
Secure Communications
VamosPago uses encrypted connections to protect information transmitted between merchants, users, and our platform. Merchants should only communicate with VamosPago services through the official endpoints listed in our Developer Documentation.
API and Account Security
API requests must follow the authentication and signing requirements described in our Developer Documentation. API credentials must be stored securely and must never be exposed in client-side code, public repositories, emails, or support requests.
Access Protection
Access to merchant accounts and operational systems is restricted according to business responsibilities. Merchants are responsible for maintaining appropriate permissions for their users and promptly removing access that is no longer required.
Transaction Monitoring
VamosPago applies transaction monitoring and risk-control measures designed to identify suspicious activity and reduce payment fraud. The controls applied may vary by product, payment method, merchant profile, and market.
Data Protection
We seek to limit the collection and use of personal and payment data to what is necessary to provide our services, comply with applicable requirements, prevent fraud, and protect the integrity of the platform.
Service Resilience
Our operational processes are designed to support service continuity, incident management, backup, and recovery. Actual service commitments are governed by the applicable merchant agreement or service-level agreement.
Merchant Responsibilities
Merchants must:
- Protect account credentials and API keys;
- Use secure devices and network connections;
- Apply appropriate user-access controls;
- Keep integration libraries and systems up to date;
- Validate webhook notifications and API responses;
- Never request or transmit passwords, one-time codes, or card security codes through email or chat; and
- Notify VamosPago promptly of suspected unauthorized activity.
Card Data and PCI DSS
PCI DSS requirements depend on how a merchant integrates and whether the merchant directly collects, processes, stores, or transmits cardholder data.
Unless VamosPago has confirmed otherwise in writing, merchants should not store sensitive authentication data or submit raw card information through an integration that is not specifically designed for that purpose. Refer to our Developer Documentation for the requirements applicable to your integration.
Report a Security Concern
If you believe that your merchant account, API credentials, or a VamosPago service may have been compromised, contact your assigned account manager or the official Merchant Support channel immediately.
When reporting a concern, do not include passwords, complete card numbers, CVV/CVC values, private keys, or one-time authentication codes.