---
title: Security
slug: en/security
description: Information about the security standards and regulations for services and products owned by NICEPAY
image: https://archbee-image-uploads.s3.amazonaws.com/ZHvSjR5ZrsoxwKbJa3xmo/FZ_KCnC_vxf6q2URBkM93_microsoftteams-image.png
icon: {"faIcon":"fa-solid fa-shield"}
docTags: 
createdAt: 2024-03-28T03:07:58.088Z
---

# About Services Security of NICEPAY

***

As a transaction services provider in Indonesia, NICEPAY is obligated to meet the security standards during transactions to avoid suspicious activity that can harm any parties, both Customers and Merchants. The following are information regarding the security of transaction services available in NICEPAY.



## Security Standards and Regulations

### Security Features

NICEPAY has [FDS](docId\:gcdGE1D_xVhLndpfBdD8m) and [3Ds](docId\:V7ZW1Gbz9-9za_lzVU3KY) systems as a security features for secure transaction using Credit Card.



### Compliance

NICEPAY already has local transaction security certifications and licenses, such as the PJP (*Penyedia Jasa Pembayaran*) Category 2 permit related to Payment Gateway and Category 3 permit related to PTD (*Penyelenggara Transfer Dana*) from Bank Indonesia, Domestic PSE from Kominfo, as well as international compliance certifications, namely PCI DSS Level 1 and PCI 3DS.



## Role and Responsibility on Protection

Transaction protection becomes the responsibility and role of all parties, not only NICEPAY.  Merchant responsible on maintain the transmission data security, identify users and authenticate access to system component.&#x20;

The following is the list of Merchant responsibility on maintain the transaction security.

1. Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks
   - Processes and mechanisms for protecting cardholder data with strong cryptography during transmission over open, public networks are defined and documented
   - PAN is protected with strong cryptography during transmission.
   - Strong cryptography and security protocols are implemented as follows to safeguard PAN during transmission over open, public networks:
     - Only trusted keys and certificates are accepted.
     - Certificates used to safeguard PAN during transmission over open, public networks are confirmed as valid and are not expired or revoked. This bullet is a best practice until its effective date; refer to applicability notes below for details.
     - The protocol in use supports only secure versions or configurations and does not support fallback to, or use of insecure versions, algorithms, key sizes, or implementations.
     - The encryption strength is appropriate for the encryption methodology in use.
   - An inventory of the entity’s trusted keys and certificates used to protect PAN during transmission is maintained.
2. Identify Users and Authenticate Access to System Components
   - User identification and related accounts for users and administrators are strictly managed throughout an account’s lifecycle.
   - All users are assigned a unique ID before access to system components or cardholder data is allowed
   - Group, shared, or generic accounts, or other shared authentication credentials are only used when necessary on an exception basis, and are managed as follows:
     - Account use is prevented unless needed for an exceptional circumstance.
     - Use is limited to the time needed for the exceptional circumstance.
     - Business justification for use is documented.
     - Use is explicitly approved by management.
     - Individual user identity is confirmed before access to an account is granted.
     - Every action taken is attributable to an individual use



## NICEPAY Products Security

### Data Transmission

NICEPAY has used HTTPS on all API endpoints to maintain the security of data transmission in transactions between Merchants and Customers, Merchants with NICEPAY, and other parties connected to the NICEPAY system.



### Authentication

NICEPAY has special authentication in verifying data in the system for SNAP and non-SNAP transactions. In SNAP transactions, authentication uses the [Request Access Token API - SNAP](docId:92feymrQs_iebHXrfgXUq) by following the provisions of the Indonesian Payment Association. While in non-SNAP transactions, authentication uses a [Merchant Token](docId:-9AHumzBwZozg905Z3IoR) with the `SHA-256` hashing method.



### Callback Handling

Callback Handling is used by the Merchants to verify the payment of transactions to the NICEPAY.



### Whitelist IP

:::Iframe{iframeHeight="0" code="<!-- <p>paste iframe code here</p> --> Merchant﻿s can Whitelist IPs to increase their system ﻿security if needed. Please contact <a style=&#x22;color:blue;text-decoration-line:underline&#x22; href=&#x22;mailto:cs@nicepay.co.id&#x22;>NICEPAY Customer Service</a> to get list of NICEPAY IP."}

:::



### Notification and Transaction Status

Every transaction process that runs on the NICEPAY system has an automatic notifications which contain transaction information and status that varies according to the stage of a transaction. We suggests Merchants to check the notifications sent and transaction status using API Status Inquiry regularly to avoid notification injection from irresponsible parties.

List of NICEPAY Status Inquiry API:

| **API Version** | **API Link**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| --------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SNAP Version    | - [Check Status Transaction - API Virtual Account SNAP](docId\:QDN7CGVv26s2XEibfWg1U)
- [Check Status Transaction - API QRIS SNAP](docId\:a0i6Lo4dvBo6Ih5Ql6nDA)
- [Check Status Transaction - API E-Wallet (Direct Debit) SNAP](docId\:za7aN0HE8C3-2OiXvdlNa)
- [Inquiry - API Payout (Disbursement) SNAP](docId\:Ge22wm18E02qRwDgBWMz_)
- [Inquiry History - API SNAP Provider](docId\:Q6WfjfF2UPKVDlms56Io5)
- [Inquiry - API NICEPAY Inquiry Virtual Account SNAP](docId\:Zltn93lAidZfGPiIf7d26)                                                                                                                                                                             |
| Version 2       | * [Status Inquiry - API Checkout](docId:7tHQVpHz6EMWEzw5_d4AN)
* [Status Inquiry - API Credit Card](docId\:fc_bkdwkeVWF2H9USOc8K)
* [Status Inquiry - API Virtual Account](docId\:iTCM3ihd_D5TJo3I0zjEn)
* [Status Inquiry - API Convenience Store](docId:79r7V9yNeNETFidqqVmkK)
* [Status Inquiry - API Direct Debit](docId\:b6ctfH0SI5nTzUljBWTNd)
* [Status Inquiry - API E-Wallet](docId\:tegPDwIwlQPwiIK9VV3r4)
* [Status Inquiry - API Payloan](docId\:IKBNpmY56GWW3hk0V3EmU)
* [Status Inquiry - API GPN](docId\:Z6mZ313PnsR5weUnYLyTa)
* [Status Inquiry - API QRIS](docId\:I34G2MHSezzv2Y4d1BJ7Y)
* [Inquiry - API Payout (Disbursement)](docId\:UChkZOmsXvxzdCkNfMUzd) |
| Version 1       | [V1 Check Transaction Status](docId\:B-HqVi5GBNS-yxcEXEM2a)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

:::hint{type="info"}
Notification Injection is one of the security vulnerabilities when an attacker sends a notification that is not supposed to be sent to the systems.
:::



## Security Maintenance

### Bug Bounty Program

NICEPAY appreciates all forms of information regarding security system issues submitted. However, NICEPAY does not have a Bug Bounty program and does not provide any rewards. Though NICEPAY does not currently have a Bug Bounty program for public participation, we may consider it in the future.

NICEPAY will continue to evaluate and improve the security of our system based on national and international standards as a top priority to protect the confidentiality of information for every transaction that runs in our system . For further information regarding the Bug Bounty program and security of the NICEPAY system in the future, please visit NICEPAY official [website](https://nicepay.co.id/) and social media.

