Our Security Approach
Secure Communications
VamosPago uses encrypted connections to protect information transmitted between merchants, users, and our platform. Merchants should only communicate with VamosPago services through the official endpoints listed in our developer documentation.
API and Account Security
API requests must follow the authentication and signing requirements described in our developer documentation. API credentials must be stored securely and must never be exposed in client-side code, public repositories, emails, or support requests.
Access Protection
Access to merchant accounts and operational systems is restricted according to business responsibilities. Merchants are responsible for maintaining appropriate permissions for their users and promptly removing access that is no longer required.
Transaction Monitoring
VamosPago applies transaction monitoring and risk-control measures designed to identify suspicious activity and reduce payment fraud. The controls applied may vary by product, payment method, merchant profile, and market.
Data Protection
We seek to limit the collection and use of personal and payment data to what is necessary to provide our services, comply with applicable requirements, prevent fraud, and protect the integrity of the platform.
Service Resilience
Our operational processes are designed to support service continuity, incident management, backup, and recovery. Actual service commitments are governed by the applicable merchant agreement or service-level agreement.
Merchant Responsibilities
Merchants must:
- Protect account credentials and API keys;
- Use secure devices and network connections;
- Apply appropriate user-access controls;
- Keep integration libraries and systems up to date;
- Validate webhook notifications and API responses;
- Never request or transmit passwords, one-time codes, or card security codes through email or chat; and
- Notify VamosPago promptly of suspected unauthorized activity.
Impersonation and Fraud Prevention
Unauthorized third parties may attempt to impersonate VamosPago by using our name, logo, website design, employee identities, social media profiles, or similar-looking domain names.
Official website: https://www.vamospago.com
Official VamosPago websites and services use the vamospago.com domain or subdomains ending exactly in .vamospago.com. The use of the VamosPago name, logo, branding, or a similar domain does not prove that a website, account, message, or individual is authorized by VamosPago.
Before providing information, accessing an account, or following payment instructions, always verify:
- The complete domain shown in your browser's address bar;
- The sender's complete email address;
- The identity of the contracting entity or responsible service provider; and
- Any payment instructions against previously verified official records.
VamosPago will never request the following through email, Telegram, social media, or general chat:
- Passwords;
- One-time authentication codes;
- Private keys or API secrets;
- Complete payment card numbers;
- CVV or CVC security codes; or
- Payments to personal bank accounts.
Do not access your account or provide information through links received from unknown or unverified sources. A padlock symbol or HTTPS connection alone does not confirm that a website is operated by VamosPago.
If you receive a suspicious message or discover a website, account, or individual claiming to represent VamosPago, do not provide information or send funds. Report the incident to support@vamospago.com and include, where available:
- The suspicious website address;
- The sender's email address, telephone number, or account name;
- Screenshots of the message or website;
- The date and time of contact; and
- A brief description of what was requested.
Do not include passwords, authentication codes, private keys, API secrets, complete card numbers, or other sensitive credentials in your report.
PCI DSS and Payment Security
VamosPago is committed to protecting payment information and supporting secure payment integrations. PCI DSS provides a framework for safeguarding cardholder data when it is stored, processed or transmitted.
Security responsibilities depend on the services and integration used. Using a payment provider does not automatically remove a merchant's own PCI DSS obligations. For information about the PCI DSS assessment scope relevant to your service and the responsibilities of each party, please contact support@vamospago.com.
Report a Security Concern
If you believe that your merchant account, API credentials, or a VamosPago service may have been compromised, contact your assigned account manager or the official Merchant Support channel immediately.
When reporting a concern, do not include passwords, complete card numbers, CVV/CVC values, private keys, or one-time authentication codes.