Security
About Services Security of NICEPAY
As a transaction services provider in Indonesia, NICEPAY is obligated to meet the security standards during transactions to avoid suspicious activity that can harm any parties, both Customers and Merchants. The following are information regarding the security of transaction services available in NICEPAY.
Security Standards and Regulations
Security Features
NICEPAY has FDS and 3Ds systems as a security features for secure transaction using Credit Card.
Compliance
NICEPAY already has local transaction security certifications and licenses, such as the PJP (Penyedia Jasa Pembayaran) Category 2 permit related to Payment Gateway and Category 3 permit related to PTD (Penyelenggara Transfer Dana) from Bank Indonesia, Domestic PSE from Kominfo, as well as international compliance certifications, namely PCI DSS Level 1 and PCI 3DS.
Role and Responsibility on Protection
Transaction protection becomes the responsibility and role of all parties, not only NICEPAY. Merchant responsible on maintain the transmission data security, identify users and authenticate access to system component.
The following is the list of Merchant responsibility on maintain the transaction security.
- Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks
- Processes and mechanisms for protecting cardholder data with strong cryptography during transmission over open, public networks are defined and documented
- PAN is protected with strong cryptography during transmission.
- Strong cryptography and security protocols are implemented as follows to safeguard PAN during transmission over open, public networks:
- Only trusted keys and certificates are accepted.
- Certificates used to safeguard PAN during transmission over open, public networks are confirmed as valid and are not expired or revoked. This bullet is a best practice until its effective date; refer to applicability notes below for details.
- The protocol in use supports only secure versions or configurations and does not support fallback to, or use of insecure versions, algorithms, key sizes, or implementations.
- The encryption strength is appropriate for the encryption methodology in use.
- An inventory of the entity’s trusted keys and certificates used to protect PAN during transmission is maintained.
- Identify Users and Authenticate Access to System Components
- User identification and related accounts for users and administrators are strictly managed throughout an account’s lifecycle.
- All users are assigned a unique ID before access to system components or cardholder data is allowed
- Group, shared, or generic accounts, or other shared authentication credentials are only used when necessary on an exception basis, and are managed as follows:
- Account use is prevented unless needed for an exceptional circumstance.
- Use is limited to the time needed for the exceptional circumstance.
- Business justification for use is documented.
- Use is explicitly approved by management.
- Individual user identity is confirmed before access to an account is granted.
- Every action taken is attributable to an individual use
NICEPAY Products Security
Data Transmission
NICEPAY has used HTTPS on all API endpoints to maintain the security of data transmission in transactions between Merchants and Customers, Merchants with NICEPAY, and other parties connected to the NICEPAY system.
Authentication
NICEPAY has special authentication in verifying data in the system for SNAP and non-SNAP transactions. In SNAP transactions, authentication uses the Request Access Token API - SNAP by following the provisions of the Indonesian Payment Association. While in non-SNAP transactions, authentication uses a Merchant Token with the SHA-256 hashing method.
Callback Handling
Callback Handling is used by the Merchants to verify the payment of transactions to the NICEPAY.
Whitelist IP
Notification and Transaction Status
Every transaction process that runs on the NICEPAY system has an automatic notifications which contain transaction information and status that varies according to the stage of a transaction. We suggests Merchants to check the notifications sent and transaction status using API Status Inquiry regularly to avoid notification injection from irresponsible parties.
List of NICEPAY Status Inquiry API:
API Version | API Link |
|---|---|
SNAP Version | |
Version 2 | |
Version 1 |
Notification Injection is one of the security vulnerabilities when an attacker sends a notification that is not supposed to be sent to the systems.
Security Maintenance
Bug Bounty Program
NICEPAY appreciates all forms of information regarding security system issues submitted. However, NICEPAY does not have a Bug Bounty program and does not provide any rewards. Though NICEPAY does not currently have a Bug Bounty program for public participation, we may consider it in the future.
NICEPAY will continue to evaluate and improve the security of our system based on national and international standards as a top priority to protect the confidentiality of information for every transaction that runs in our system . For further information regarding the Bug Bounty program and security of the NICEPAY system in the future, please visit NICEPAY official website and social media.