Security

Pause. Check the page, the agreement and the reference before acting.

Most people you deal with are honest. A few careful habits protect the agreement anyway, without treating every unfamiliar page as a threat.

  • Protect your KSNumber credentials

    Your KSNumber identifies you in every agreement. Keep the way you sign in to yourself.

    • Never share your password or a one-time code, even with someone who says they are from SecurePay.
    • Sign out of devices you no longer use from your profile security page.
    • Use a screen lock on the phone you use for agreements.
  • Recognizing official SecurePay pages

    A public SecurePay page is not automatically approved by SecurePay. Read what the page says.

    • Check the public locator and the name of the profile that published the page.
    • Look for the environment label. A sandbox page is a test page and must not be paid.
    • If something reads strangely, open your agreement from the app rather than from a message.
  • Keep API secrets on servers

    Secret keys belong in server environments, never in a browser, an app bundle or a message.

    • Use sandbox keys while building.
    • Rotate a key immediately if it has been seen by anyone else.
    • Verify webhook signatures before acting on a payload.
  • Check the agreement before you act

    Pause. Check the page, the agreement and the reference before acting.

    • Read the version you are being asked to accept, not the one you read last week.
    • Check your role. Creator, payer, performer and approver are different things.
    • Keep the reference for any money action you take.
  • Avoiding duplicate payment attempts

    Most money confusion comes from a second attempt made during an unresolved first attempt.

    • Check the current state before paying again.
    • If the state is pending or under reconciliation, wait.
    • Keep the reference from the first attempt so both can be matched.
  • Reporting a page that concerns you

    Not every unfamiliar page is dishonest, but a page that misuses the SecurePay name should be reported.

    • Copy the public locator of the page.
    • Do not pay while you are unsure.
    • Send the details through the support request prototype with the locator included.

About the examples on this page

Every example, record and status here is demonstration content and is labelled mock. Sandbox records behave realistically but move no money. Live records come from real activity. These pages are not live customer cases.