Public website controls
The website is delivered over HTTPS with restrictive browser headers. The enquiry form is intended only for business contact and project information; it must not be used for cardholder data, credentials, one-time codes or identity documents.
Payment-service principles
Minimise sensitive data
Integration design should limit the sensitive payment information handled directly by merchant systems and follow the requirements of the approved operating setup.
Verify server to server
Merchant applications should authenticate requests, protect credentials and verify payment results independently of customer-facing redirects.
Keep events traceable
Consistent transaction references and reviewable event histories support fraud response, refunds, reconciliation and support.
Control access
Production access should follow job responsibility, strong authentication, credential rotation and removal of access when no longer required.
Report a security concern
Email security@paymentgatewayinbangladesh.com with the affected URL, reproducible steps and potential impact. Do not include live payment data.