Security

Secure payments

Card details never touch ELVPro: seven processors, all hosted or redirect flows, with 3-D Secure and verified callbacks.

At a glance

Plan
All plans
Last updated
September 2, 2026

What this covers

How money reaches your account — and what ELVPro deliberately never sees on the way.

How it works in ELVPro

No card data, ever

Every processor ELVPro supports uses a hosted payment page or a redirect: the buyer types their card number on the bank's or the processor's own page, never on your storefront. Nothing card-shaped is stored, logged or forwarded by us — which is what keeps your PCI DSS obligations at the lightest tier.

Seven processors, one seam

Stripe, LibraPay, EuPlătesc, ING WebPay, BT iPay, PayU and NETOPIA. A yard picks one; switching later does not strand the payments taken through the previous one.

Strong customer authentication

3-D Secure is applied by the processor, so the buyer gets their own bank's challenge.

Nothing is believed until it is verified

A "payment successful" message is acted on only once it is proven: an HMAC signature recomputed over the processor's exact field order, a JWT checked against the processor's public key, or a fresh query to the processor's own API asking what it thinks happened. An unverified callback creates no order.

Settled exactly once

The server-to-server notification, the buyer's return to the shop and a scheduled reconcile sweep all lead to the same place: whichever arrives first settles the order, and the rest do nothing. A buyer who closes the tab mid-payment still gets their order.

A trail on both sides

Every exchange with a processor is recorded — direction, endpoint, status, duration, outcome — with credentials, signatures and anything card-shaped masked before storage. Payloads are purged after 90 days; the metadata stays.

Stored secrets are encrypted

Processor keys live encrypted in the database and are never shown back in full once saved.

When it happens

When this runs, and what it does
When What happens
At checkout the signed hand-off to the processor.
On the callback signature or JWT verification, or a status re-query, before anything is created.
Every few minutes the reconcile sweep, for processors that never push a notification, or when one goes missing.
At fulfilment if the part was lost between payment and dispatch, the payment is refunded automatically where the processor offers a refund API, and flagged loudly for a manual refund where it does not.

Why it matters

The moment card data touches your systems, PCI DSS becomes your problem and a breach becomes catastrophic. Keeping the card on the processor's page, and refusing to trust any message about a payment until it has been cryptographically verified or re-queried, removes both the most expensive risk and the most common fraud.

What we don't claim

Two processors (LibraPay and NETOPIA) expose no refund API today, so a refund there is a deliberate manual step in the bank's panel — ELVPro flags it rather than pretending it happened. ELVPro is not a payment institution: your contract, your settlement and your fees are with the processor you choose.

Questions about security or compliance?

We will gladly walk you through how ELVPro handles your data — or fill in your compliance questionnaire.