Environment separation
Sandbox and Live have separate credentials and operational flows.
Security
Pal Plus Business separates environments, scopes credentials, records important actions and uses signed request and webhook patterns for supported integrations.
Sandbox and Live have separate credentials and operational flows.
API keys and company roles are limited to the access required for their purpose.
Supported API requests and webhook events use cryptographic signing patterns to reduce tampering risk.
Sensitive access and operational changes are designed to leave an auditable record.
API nonces and webhook event IDs are de-duplicated, with short timestamp windows for signed requests.
Webhook targets must be public HTTPS destinations; private-network DNS targets and redirects are rejected.
Security guidance
Keep privileged credentials server-side, rotate them when exposure is suspected, and verify webhook signatures before acting on events.