Oyaka reads data from your gateway, processor and alert provider. Here is exactly what we see, what we store and how we protect it.
We match records using the last four digits of a card, the amount and the date. That keeps full card data out of our systems entirely.
Data is encrypted in transit (TLS 1.2 or newer) and at rest. API keys get an extra layer of encryption with keys managed in AWS.
We ask for the narrowest access each system allows. Refunds and dispute submissions only happen when someone on your team clicks the button.
Every refund, dispute and settings change is recorded with who did it and when. Owners can review the full history.
Required for every user, with roles so only the right people can move money.
Every record is tied to one merchant account, and every request is checked against it. Disconnect and export at any time.
Private networks, daily backups kept for 14 days, and monitoring that alerts our team to failures.
SOC 2 Type I audit planned for [DATE]. Need our security questionnaire answered or a data processing agreement? We'll send them.