{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-platform/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Security","llmstxt":{"title":"Glomopay developer documentation","description":"Cross-border payments APIs, organised by product. Each product section carries both the explanation of its objects and the job-shaped integration guides that set them up.","details":{"content":"How to use these docs:\n\n- Get started is the front door. It carries a routing table from\n  \"what are you building\" to the page that builds it, plus how to get\n  API keys.\n- The product sections - Payin, Payout, Multi-currency accounts,\n  Verification, Request for Information (RFI) - each hold two kinds of page.\n  Pages titled as a noun (\"Subscriptions\", \"Bank Transfer\") explain what\n  an object is. Pages titled as a job (\"Set up recurring subscriptions\",\n  \"Collect LRS remittances from India\") are complete integration flows\n  and live one level under the object they set up. Match a user's goal\n  against the job-shaped titles first.\n- Reports and Identity and Access Management are the two subjects with no\n  API counterpart. There are no endpoints for reports, users, roles or\n  invites; both pages document the merchant dashboard. A dashboard\n  procedure for something the API also does (a refund, a payout) is NOT\n  here - it stays in the product that owns it.\n- API reference is generated from OpenAPI and carries endpoint detail.\n- The OpenAPI description itself is published as a single self-contained\n  document at /openapi.yaml, and the same document as JSON at\n  /openapi.json. Every $ref is resolved into it, so one fetch is the\n  whole contract: 61 paths, 81 operations, 68 schemas - the same\n  endpoints the API reference pages render. Fetch that instead of\n  reading the 129 pages under /api-reference/.\n- Developer resources covers what every integration touches and no single\n  product owns: auth, errors, pagination, rate limits, webhooks,\n  versioning, supported countries, quotes, and the client SDKs.\n"},"sections":[{"title":"Get started","description":"The front door. The routing table from a merchant's goal to the flow that delivers it, how to obtain API keys, and the platform glossary.","includeFiles":["**/get-started/**"]},{"title":"Payin","description":"Collecting money: customers, orders, checkout, payment links, payment methods (cards, bank transfer, pay via bank), refunds, disputes, purpose codes, fee models, custom fields, subscriptions, and resident India remittance under LRS. Includes the flows that set each up - bank transfers, subscriptions, LRS remittances, and server-to-server card payments.","includeFiles":["**/payin/**"]},{"title":"Payout","description":"Sending money: the payout life cycle, queued payouts, creating and cancelling a payout, rails, beneficiaries, purpose codes, and the action required state.","includeFiles":["**/payout/**"]},{"title":"Multi-currency accounts","description":"Holding money: balances, balance conversion, adding balance, withdrawing balance, and the settlement holiday calendar - the Indian and US bank and FX holidays on which settlement to the merchant's bank account, and money movement generally, is affected.","includeFiles":["**/multi-currency-account/**"]},{"title":"Verification","description":"Proving who someone is and that an account is theirs: KYC, bank account validation, and third-party verification (TPV) with the flow that verifies a payer's bank account.","includeFiles":["**/verification/**"]},{"title":"Request for Information (RFI)","description":"Responding to a compliance request for information, per object - payment link, order, payment, payout - plus compliance reviews and RFIs raised on already-successful payments.","includeFiles":["**/request-for-information/**"]},{"title":"Reports","description":"The downloadable and scheduled reports a merchant pulls from the dashboard for reconciliation, compliance and treasury: payment, subscription, settlement breakup, balance statement and KYC reports, plus scheduling one for recurring email delivery. Dashboard only - there is no reports API.","includeFiles":["**/reports/**"]},{"title":"Identity and Access Management","description":"Administering who can use a merchant account: one set of credentials across multiple MIDs, switching between them without logging out, the Admin / Member / Sales Partner roles and what each may see and do, and inviting a new member. Dashboard only - there is no users, roles or invites API.","includeFiles":["**/access-management/**"]},{"title":"API reference","description":"Endpoint reference generated from the Glomopay OpenAPI description.","includeFiles":["**/api-reference/**"]},{"title":"Developer resources","description":"What every integration touches and no single product owns: auth, errors, pagination, rate limits, webhooks, versioning, API validations, security, supported countries, quotes, and the client SDKs - React Native, Flutter, Android and the Unified Web SDK, with per-version references and changelogs. Reports and Identity and Access Management used to be listed here and are now their own sections.","includeFiles":["**/platform/**"]}]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"security","__idx":0},"children":["Security"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["As a financial service provider, GlomoPay prioritizes the security and privacy of your data. We are committed to maintaining a robust and secure environment, ensuring that every transaction is protected with industry-leading safeguards."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Our users trust GlomoPay with their sensitive financial information, and we take this responsibility seriously. As a global payments platform, we continuously enhance our security posture to meet and exceed the stringent standards of the financial industry, providing a safe and seamless payment experience for businesses and their customers."," ","All the data at rest at GlomoPay is encrypted using AES-256 encryption."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"regulations-and-compliance","__idx":1},"children":["Regulations and Compliance"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"certifications","__idx":2},"children":["Certifications"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"soc-2-type-2-certification","__idx":3},"children":["SOC 2 Type 2 Certification"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["GlomoPay is SOC 2 Type 2 compliant, ensuring the highest standards of security, availability, and data integrity. This certification demonstrates our commitment to protecting sensitive data and maintaining a secure and reliable payments infrastructure."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["As part of our compliance, we undergo regular independent audits to verify that our security controls and processes meet industry best practices. Our systems are designed to safeguard customer data, ensuring that we operate with the highest levels of trust and transparency."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["By achieving SOC 2 Type 2 compliance, GlomoPay continues to uphold its commitment to data security and regulatory compliance, providing businesses and users with a secure payment experience."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"iso-270012022-certification","__idx":4},"children":["ISO 27001:2022 certification"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["GlomoPay is ISO 27001:2022 certified, demonstrating our commitment to industry-leading information security standards. This certification ensures that we follow best practices for data protection, risk management, and compliance, providing a secure and reliable payments infrastructure for our users."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"tls-encryption","__idx":5},"children":["TLS Encryption"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["GlomoPay employs industry-leading encryption practices to ensure the security of all transactions."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Minimum version supported is TLS 1.2"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"ip-whitelisting","__idx":6},"children":["IP Whitelisting"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For all the incoming traffic from Glomopay  please whitelist the following IP addresses in respective environments:"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"sandbox","__idx":7},"children":["Sandbox"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["34.47.199.41, 34.93.125.61 "]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"production","__idx":8},"children":["Production"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["35.200.206.17, 34.47.255.77, 34.47.195.89"]}]}]},"headings":[{"value":"Security","id":"security","depth":1},{"value":"Regulations and Compliance","id":"regulations-and-compliance","depth":2},{"value":"Certifications","id":"certifications","depth":3},{"value":"SOC 2 Type 2 Certification","id":"soc-2-type-2-certification","depth":4},{"value":"ISO 27001:2022 certification","id":"iso-270012022-certification","depth":4},{"value":"TLS Encryption","id":"tls-encryption","depth":2},{"value":"IP Whitelisting","id":"ip-whitelisting","depth":2},{"value":"Sandbox","id":"sandbox","depth":4},{"value":"Production","id":"production","depth":4}],"frontmatter":{"seo":{"title":"Security"}},"lastModified":"2026-09-22T05:15:29.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/platform/security","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}