Security

Practical controls for merchants that collect and pay out real money.

Business KYC

Merchants upload incorporation and identity documents before live access. Ops review happens in the admin portal.

Sandbox vs Live

Integrations start in sandbox. Live money movement only after verification, with the same API shapes in both environments.

HMAC-signed API

Server-to-server calls use nonce, timestamp, and HMAC signatures so credentials are not sent as bare bearer tokens alone.

Team roles

Invite staff with roles so payouts, API keys, and settings stay limited to the right people.

Settlement visibility

Available Balance excludes Today's Collection, reducing accidental payouts against funds still settling.

Session controls

Merchant portal sessions expire on inactivity and support OTP sign-in plus optional authenticator 2FA.

Need a security questionnaire or vendor review pack? Email support@klustar.io.