USDT Vouchers
Security starts on the server.
The browser never decides that a card can be delivered: only a verified OxaPay confirmation can.
Last reviewed · August 27, 2026
Payments
The merchant key remains server-side. Callbacks are checked with their HMAC SHA-512 signature and processed idempotently.
Gift codes
In production, codes must be encrypted at rest, masked by default and excluded from application logs.
Reporting
For a security issue, use the contact form and choose the Security category.