Security
Last updated: July 1, 2026
1. Overview
Verify.ge is built as a security-first OTP verification platform for Georgian businesses. This page summarizes the technical and operational controls we use to protect your data, API access, and payments.
2. Infrastructure
All customer-facing traffic is served over HTTPS with TLS 1.3. Production and development environments are separated. Infrastructure is hosted with reputable cloud providers and access is restricted to authorized personnel.
3. Authentication
Dashboard sessions use HTTP-only cookies with secure flags in production. API access uses hashed API keys shown only once at creation. JWT tokens are short-lived and refreshed automatically. We recommend rotating API keys periodically.
4. API Security
API requests are authenticated and rate-limited to prevent abuse. Idempotency keys are supported for payment order creation. Webhook deliveries can be verified using shared secrets. OTP codes are not returned in API responses after verification.
5. OTP Security
OTP codes expire after a limited time and have attempt limits. Codes are not logged in plaintext. Rate limiting protects against brute-force verification. Test phone numbers are available for development without billing charges.
6. Payment Security
Card data never touches Verify.ge servers. All card payments are processed on BOG-hosted pages under BOG's PCI-DSS scope. We store only BOG-issued tokens and masked card metadata. BOG payment webhooks are verified using cryptographic signatures before fulfillment. Privacy Policy · Compliance.
7. Data Protection
Data is encrypted in transit. Access to production systems follows least-privilege principles. OTP transaction logs and billing records are retained according to our Privacy Policy.
8. Incident Response
We maintain procedures to detect, investigate, and respond to security incidents. If a breach affects your personal data, we will notify affected customers and relevant authorities as required by applicable law.
9. Responsible Disclosure
If you discover a security vulnerability, please report it responsibly to [email protected]. Do not publicly disclose issues before we have had a reasonable opportunity to remediate them.
[email protected]
10. Your Responsibilities
Keep your API keys confidential. Obtain end-user consent before sending OTPs. Do not log or store OTP codes in your application. Use HTTPS for all integrations. Report suspected unauthorized access immediately.