How UniWeb protects merchants and payment operations.
We publish the controls that matter for Indian businesses: transport security, KYC gates, audit trails, partner verification and a named grievance path — without claiming licences we do not hold.
HTTPS everywhere
Dashboard, checkout and API traffic use TLS. Session cookies are protected; idle timeout applies on merchant and admin portals.
KYC before Live Mode
Live collections require verified documents, bank account, website review, video KYC where required, and signed merchant agreement.
Webhook & API integrity
Gateway webhooks are signature-checked. Merchant outbound webhooks use HMAC. API keys are separated for Test and Live.
Audit & dual control (interim)
Sensitive KYC and Live activation use checker flows and an immutable audit log where wired. Full bank-grade dual-approve is built only when a named deal requires it — roles alone are not a fake dual-control product.
Velocity & fraud signals
Failed login and non-QR payment abuse are rate-limited.
Private KYC storage
New KYC uploads are stored outside the public web root with access limited to authorized staff viewers.
What we are — and what we are not
Uniweb Technologist PVT LTD operates a merchant technology platform. Live acquiring, cards, UPI settlement and payouts are provided through contracted banks and payment partners after commercial activation.
We do not claim that UniWeb independently holds an RBI Payment Aggregator licence, a banking licence, or a card-network membership. Those claims appear only when the relevant licence or partner agreement is in force and disclosed here.
We do not offer a consumer PPI wallet or an NBFC lending product. Personal data is processed in India under the DPDP Act, 2023 — see the Privacy Policy.
Where the evidence already lives
Map buyer diligence questions to these controls. Do not invent PCI Level 1, ISO 27001 or SOC 2 badges. See also the PCI readiness path.
Q: TLS / transport?
HTTPS / TLS on dashboard, checkout and API. See this page and the Privacy Policy.
Q: Who holds card data?
Licensed partners on their hosted pages. UniWeb does not store PAN/CVV. We do not claim UniWeb PCI Level 1.
Q: Access control?
Merchants sit under UniWeb Admin only. Merchant team roles and staff roles. Partner keys stay on Super Admin / Ops Partner Registry — partners are rails, not merchant owners. No partner login portal.
Q: Audit trail?
Immutable money-action log. Checker on Live KYC where wired. Export by date from Admin → Audit Log when needed.
Q: Webhooks?
HMAC-SHA256 X-UniWeb-Signature. Copy-paste verify on API Settings. Test vs Live API keys are separate.
Q: Data residency?
Personal data processed in India under the DPDP Act, 2023. KYC files are not on the public web root.
Q: Certifications / badges?
We do not display PCI DSS, ISO 27001 or SOC 2 until an independent assessment exists. Card rails sit with licensed partners.
Q: Dual control?
Staff roles + audit log today. Expand dual-approve only for a named contract (see branding / deal checklist WL-14).
Badges we will show only when true
We do not display PCI DSS, ISO 27001 or SOC 2 badges until an independent assessment is completed. Partner gateways (Razorpay, Cashfree, PayU and banks) maintain their own PCI and network certifications for card-present and card-not-present rails.
Named contact for complaints
Include merchant code and transaction/settlement ID. Do not send OTPs, PINs or passwords. Escalation: reply on the same ticket within 7 days if unresolved.
Open contact form