Güvenlik, ürünün altındaki üründür
Bu platform üzerinden her saniye para ve kişisel veri hareket ediyor. İşte bugün her ikisini de gerçekten koruyan şey — uydurma sertifikalar değil, sadece inşa edilenler.
İddia değil, inşa
Bugün gerçekten yerinde olan
Kart verisi bize hiç dokunmaz
Kart numaraları, lisanslı bir ödeme sağlayıcı tarafından işlenen bir sayfada girilir. DorskoPay'in kendi sistemleri ham kart verisini asla saklamaz.
HMAC imzalı webhook'lar
Her webhook olayı HMAC-SHA256 ile imzalanır ve zaman damgalanır; böylece uç noktanız olayın bizden geldiğini ve tekrar oynatılmadığını doğrulayabilir.
Hash'lenmiş, kapsamlı API anahtarları
API anahtarları saklamada hash'lenir ve panelinizden istediğiniz zaman tek tek iptal edilebilir.
Eksiksiz yönetici denetim kaydı
Veri değiştiren her yönetici işlemi — iadeler, komisyon değişiklikleri, hesap askıya almaları — kim, ne ve ne zaman bilgisiyle kaydedilir.
Oturum açma etkinliği kaydı
Başarılı veya başarısız her oturum açma denemesi, IP adresi ve cihazla birlikte kaydedilir — Ayarlar'da size görünür.
Varsayılan olarak sandbox
Tek bir gerçek işlem gerçekleşmeden önce tüm entegrasyonunuzu — ödeme sayfası, abonelikler, webhook'lar — test edebilirsiniz.
Mimari
Gerçekte nasıl inşa edildi
-
lock
Aktarım sırasında şifrelenir
Platforma yapılan her bağlantı TLS üzerinden çalışır — ödeme sayfası, panel ve API dahil.
-
key
Hash'lenmiş, iptal edilebilir API anahtarları
API anahtarları saklamada hash'lenir, hesabınıza kapsamlanır ve istediğiniz zaman tek tek iptal edilebilir.
-
shield_lock
Sahiplik kapsamlı veri erişimi
Satıcı panelleri yalnızca o satıcının kendi verisini sorgular — bu sadece arayüzde değil, veritabanı sorgusu düzeyinde uygulanır.
-
webhook
İmzalı webhook'lar
Her webhook bir HMAC-SHA256 imzası ve zaman damgası taşır; böylece uç noktanız özgünlüğü doğrulayabilir ve tekrarları reddedebilir.
-
history
Audit logging
Every mutating admin action is written to an audit trail with the actor, the target and the timestamp — refunds, commission changes, approvals and suspensions included.
-
vpn_key
Secrets management
Credentials and provider keys are held in environment configuration outside the code repository. A managed secrets store is planned as part of the production rollout.
-
admin_panel_settings
Restricted production access
Administrative capability is role-scoped inside the application. Formal, documented production access control is planned as part of the production rollout.
-
fact_check
Supplier KYB controls
Sellers are verified on company, ownership, product and banking details before production access. Production identity verification is designed to run through an approved third-party verification provider; sandbox verification flows may be simulated.
Her ödeme
Eksiksiz işlem kaydı — brüt, vergi, komisyon, net, durum
Her yönetici işlemi
Kimin, hangi hesapta, neyi ve ne zaman değiştirdiği
Her oturum açma
Başarı veya başarısızlık, IP adresi, cihaz
Her webhook
Teslimat denemesi, yanıt, imzalı yük
Production controls
Specified, and waiting on a dependency
These controls are designed and documented but depend on infrastructure that is not yet in place. They are listed here as pending, not as implemented.
| Control | Status | Depends on |
|---|---|---|
| Hosted card fields and tokenisation | Not live | The acquiring or gateway partner that ultimately processes card payments. No raw card number or security code is stored on DorskoPay systems today, and none is intended to be. |
| PCI DSS scope determination | Not determined | The acquirer and gateway selection. The applicable SAQ and any AoC requirement follow from that architecture; we do not claim a level before it is fixed. |
| Production identity verification | Integrated, not enabled | A contracted identity verification provider. The platform ships with verification simulated and no provider credentials configured. |
| Acquirer-side fraud tooling and 3-D Secure | Not live | The acquiring partner. Platform-side velocity, device and risk-flag controls run today; scheme-level authentication does not. |
| Managed secrets store | Planned | Production hosting decisions. Credentials are currently held in environment configuration outside the code repository. |
| Formal production access control and change management | Partially implemented | Documented procedures are in place internally; role-scoped administrative capability is enforced in the application. Independent review is pending. |
| Independent penetration test and security audit | Not performed | Scheduling with an external testing provider. No third party has assessed the platform to date, and we do not imply otherwise. |
| Uptime and availability monitoring | Not live | Production monitoring tooling. The status page reflects this today rather than reporting figures we do not measure. |
DorskoPay maintains internal information security, incident response, business continuity and data retention policies. They are internal documents rather than published pages, and are available to a payment partner, an auditor or a customer running a vendor security review on request.
Nereye gidiyoruz
Resmi sertifikalar: yol haritasında, henüz iddia edilmiyor
PCI DSS
Henüz sertifikalı değil. Kart verisi lisanslı bir ödeme sağlayıcı tarafından işlenir, sistemlerimizde saklanmaz.
SOC 2
Henüz onaylanmadı. Resmi üçüncü taraf güvenlik denetimleri, platform olgunlaştıkça bir hedeftir; bugün öne sürdüğümüz bir iddia değildir.
ISO 27001
Henüz sertifikalı değil. Hak etmediğimiz bir rozeti göstermektense bunu söylemeyi tercih ederiz.
Sorumlu bildirim
Bir güvenlik açığı mı buldunuz? Bize doğrudan e-posta gönderin — her rapor bir kişi tarafından okunur.
Bir tedarikçi güvenlik incelemesi mi yapıyorsunuz? Bize e-posta gönderin — bugün neyin mevcut olduğu ve neyin hâlâ inşa edildiği konusunda dürüstçe yanıtlayalım.
Bize her şeyi sorun arrow_forwardGüven,
milisaniyeler içinde kazanılır.
Her işlem, her webhook, her oturum açma — kart ağlarının bizi tuttuğu aynı standartlarla korunur.
Ücretsiz sandbox hesabı · İstediğiniz zaman iptal edin · Planlı ödemeler, mutabakat ve rezerv koşullarına tabidir