P+ Pal PlusBusiness
العربية

Security

Security is built into the account, API and operational layers.

Pal Plus Business separates environments, scopes credentials, records important actions and uses signed request and webhook patterns for supported integrations.

1

Environment separation

Sandbox and Live have separate credentials and operational flows.

2

Scoped access

API keys and company roles are limited to the access required for their purpose.

3

Signed traffic

Supported API requests and webhook events use cryptographic signing patterns to reduce tampering risk.

4

Auditability

Sensitive access and operational changes are designed to leave an auditable record.

5

Replay protection

API nonces and webhook event IDs are de-duplicated, with short timestamp windows for signed requests.

6

Outbound webhook safety

Webhook targets must be public HTTPS destinations; private-network DNS targets and redirects are rejected.

Security guidance

Never place Live secrets in browser or mobile client code.

Keep privileged credentials server-side, rotate them when exposure is suspected, and verify webhook signatures before acting on events.

Developer security flow