Card authenticationIdentity & business verificationPublic policy centre
Card & payment security
Every payment connects a chain of trust.
Card networks, payment providers and issuing banks each have a different role. Understanding those roles helps you make informed decisions about payment security.
01 / PAYMENTS
VISA
Visa Secure
Uses EMV 3-D Secure to help the issuing bank authenticate the cardholder. Depending on risk, the bank may request approval in its app or another verification step.
Issuer authentication
Helps verify the identity of the cardholder
Additional steps depend on the bank and transaction
A security standard for organisations that store, process or transmit cardholder data. Its scope depends on the payment flow and the parties that access the data.
What does card protection mean? Visa Secure and Mastercard Identity Check are cardholder authentication programmes. They do not provide insurance, a government guarantee or a promise to refund every transaction. Availability through NeroPay must be confirmed for your product, country, payment provider and bank.
Fraud & risk
Understand risk. Make informed decisions.
Payment security involves multiple checks. Account information, payment events and further review, where needed, all contribute to an informed assessment.
02 / RISK
Payment event checks
Payment notifications need to match the correct transaction. Validating events and checking payment identifiers can help reduce the risk of misleading notifications.
Identity, business details and trading activity form the basis of verification. Further information or documents may be requested depending on the account.
Keep records of orders, deliveries and customer communications. Evidence requirements and dispute deadlines depend on card scheme rules and the applicable service terms.
No fraud control eliminates every risk. An authorised payment may still be subject to a dispute or chargeback.
Cyber security
Security at both ends of the connection.
Controls applied by developers and businesses together help build more secure payment integrations.
03 / SECURITY
The foundations of integration security
Keep API keys on your server, validate incoming notifications and grant only the access required. Confirm payment outcomes against server records rather than relying on a browser redirect.
Access managementApply the least-privilege principle
TraceabilityKeep event & transaction records
Protect your account
Use a unique password, enable the security options available on your account and restrict access to authorised people. Check the domain of any link sent in NeroPay’s name.
Report suspected unauthorised access, unexpected transactions or security vulnerabilities to the support team. Do not include passwords, full card numbers, CVVs or secret API keys in your initial message.
NeroPay collects personal and business details during account registration. Identity verification is a separate step completed through your dashboard after registration.
04 / IDENTITY
01 — REGISTER
Create your account
Enter your contact details and authorised representative’s information, then review the service terms.
02 — BUSINESS
Tell us about your business
Provide your business type, trading activity and business address.
03 — VERIFY
Provide the requested details
Follow the identity verification and account setup steps shown in your dashboard.
04 — FOLLOW UP
Follow your review
Respond to further document requests and review your account and payment terms.
Verification requirements and processing times may vary by country, product and account status. Read the registration guide ↗
Regulation & compliance
Clarity about coverage matters.
The regulatory scope of a payment service depends on the legal entity providing it, the country and the financial partners involved.
05 / COMPLIANCE
Entity & country specific
Licensing & regulatory scope
Check the service provider named in your agreement against any authorisation or registration number and the regulator’s official register. Company registration alone is not a financial services licence.
Identity and business documents form part of account reviews. Applicable anti-money laundering requirements and further checks depend on the scope of the service.
Strong customer authentication may be required in relevant markets. The 3-D Secure flow, exemptions and issuing bank’s decision can vary between payments.
Check the financial protections that apply. Review the relevant service agreement for how funds are held and protected, payout schedules and any deposit protection. This centre does not claim that NeroPay is government-guaranteed or licensed in every country.
Data privacy
Understand how your data is used.
Read the privacy documents to learn what information is collected, why it is used and how to exercise your rights.
06 / PRIVACY
Purposes of processing
The privacy policy explains the personal information used for account registration, service delivery and verification.
Review the relevant policy for data recipients, international transfers and retention terms. Request further information where needed for your organisation’s review.
Read public policies or request information for your organisation’s security review.
07 / DOCUMENTS
Public documents & information requests
No documents found in this category.
Request links open a draft in your email application. A listing here does not confirm that a report is available or that a certification is held. The team will confirm availability, scope and confidentiality requirements.
Frequently asked questions
Clear answers to your questions.
08 / FAQ
Do Visa or Mastercard guarantee my money?
Visa Secure and Mastercard Identity Check help authenticate cardholders. These programmes do not provide refunds, insurance or government guarantees for every transaction. Dispute rights and responsibilities depend on the transaction and applicable terms.
Does NeroPay hold PCI DSS, ISO 27001 or SOC 2 documentation?
This page does not assert an unverified certification or audit result for NeroPay. Ask the team for current documentation, including the legal entity covered, scope and validity, to support your review.
Why are identity or business documents requested?
Documents help verify the account holder and business details. Information requests and further checks may vary by country, service and account status. Follow the current requirements in your dashboard.
Can a payment that passes fraud checks still be disputed?
Yes. Authentication and risk controls do not guarantee that a payment will remain undisputed. Keep order, delivery and customer consent records, and observe the stated deadlines if a dispute arises.
How do I request documents for a business security review?
Use the relevant request link in the document centre. Specify the service, country and document scope you wish to review. Send the request through your email application; additional confidentiality terms may apply to sensitive documents.
Safer together
Let’s talk about security.
Ask for information, request documents for your business or report something suspicious.