1Introduction
EXICASH SDN BHD ("EXICASH", "we", "us", or "our") is committed to protecting the confidentiality, integrity, and availability of our technology platform, merchant dashboard, APIs, plugins, webhooks, payment links, QR payment tools, reconciliation dashboard, reporting tools, fraud monitoring tools, white-label frontend, onboarding documents, transaction-related data, and support systems.
This Information Security Policy / Security Statement ("Security Statement") explains the security practices, responsibilities, limitations, and obligations that apply when merchants, authorised users, partners, service providers, and other users access or use EXICASH services.
EXICASH provides technology, integration, dashboard, reporting, onboarding support, communication support, and technical support only. Regulated payment processing, acquiring, settlement, payout, refund processing, chargeback handling, transaction reversal, transaction holding, and related regulated payment services are provided by licensed or registered third-party payment partners where applicable.
This Security Statement should be read together with EXICASH's Terms of Service, Privacy Policy, Partner / Third-Party Payment Provider Disclosure, Data Processing Agreement / Data Protection Addendum, AML/CFT & Sanctions Compliance Statement, Anti-Bribery / Anti-Corruption Policy, Referral Partner Agreement, and any other policies issued by EXICASH from time to time.
2Purpose of This Security Statement
The purpose of this Security Statement is to:
- explain EXICASH's approach to information security;
- protect merchant, consumer, transaction, onboarding, API, webhook, and support data;
- set clear responsibilities for merchants and authorised users;
- reduce the risk of fraud, unauthorised access, credential misuse, data leakage, and prohibited activity;
- support secure use of EXICASH's platform, APIs, dashboard, plugins, and payment technology;
- clarify the security limitations of third-party systems and licensed payment partners;
- support compliance with applicable legal, contractual, payment partner, data protection, and security requirements.
3Scope
This Security Statement applies to:
- EXICASH's website;
- merchant dashboard;
- payment gateway technology;
- payment links;
- QR payment tools;
- APIs;
- webhooks;
- plugins;
- sandbox and production environments;
- reconciliation dashboard;
- settlement report display;
- fraud monitoring tools;
- white-label frontend;
- onboarding and KYB/KYC document collection;
- support ticket systems;
- internal systems used to support EXICASH services.
This Security Statement also applies to merchants, authorised users, employees, contractors, developers, partners, referral partners, service providers, and any other person who accesses or uses EXICASH services.
4Security Governance
EXICASH maintains internal security controls designed to protect systems, data, and service operations.
Our security approach may include:
- internal access controls;
- user authentication controls;
- security monitoring;
- logging and audit trails;
- secure development practices;
- infrastructure security controls;
- vulnerability management;
- incident response procedures;
- data protection practices;
- staff confidentiality obligations;
- service provider controls;
- business continuity and recovery planning.
EXICASH may update its security controls from time to time based on changes in technology, business operations, legal requirements, payment partner requirements, threat environment, and industry practices.
5PCI Certification and Payment Security
EXICASH maintains PCI certification relevant to its role and service scope.
Where card payment functionality is made available, card processing may be handled by licensed payment partners, payment processors, tokenisation providers, card schemes, acquiring banks, or other authorised providers.
Merchants must not collect, store, process, transmit, expose, or misuse cardholder data or sensitive authentication data outside the authorised EXICASH or licensed payment partner payment flow.
Merchants must not request customers to send full card details, CVV, card PIN, online banking credentials, OTP, password, or other sensitive payment credentials through email, messaging apps, support tickets, forms, notes, screenshots, or unapproved channels.
If a merchant stores, handles, transmits, or exposes cardholder data or sensitive authentication data outside the authorised payment flow, the merchant is solely responsible for all resulting legal, regulatory, scheme, partner, security, financial, and operational consequences.
6Data Protection and Confidentiality
EXICASH applies reasonable technical, organisational, and administrative measures to protect personal data and confidential information processed through EXICASH services.
The data we protect may include:
- merchant account data;
- authorised user data;
- director, shareholder, and beneficial owner data;
- KYB/KYC documents;
- business bank account details;
- consumer payment details;
- transaction history;
- payment references;
- API logs;
- webhook logs;
- IP and device data;
- fraud and risk signals;
- support tickets;
- settlement report information;
- reconciliation data;
- partner communication records.
EXICASH personnel and authorised service providers may access such data only where necessary for service delivery, onboarding, support, security, compliance, audit, fraud prevention, legal purposes, or partner communication.
Merchants must also keep all data accessed through EXICASH services confidential and must not disclose transaction data, consumer data, API logs, webhook records, reports, or credentials to unauthorised persons.
7Access Control
Access to EXICASH systems is managed based on business need and role requirements.
EXICASH may apply controls such as:
- user account authentication;
- access permission management;
- role-based access;
- internal access restrictions;
- activity logging;
- password protection;
- account review;
- access revocation when no longer required.
Merchants are responsible for managing their own authorised users and requesting creation, amendment, or removal of sub-user/admin access where applicable.
If an authorised user leaves the merchant's organisation, changes role, no longer requires access, or is suspected of misuse, the merchant must notify EXICASH immediately so that access may be reviewed, restricted, or removed.
8Merchant Dashboard Security
Merchants must use the EXICASH dashboard securely.
Merchants and authorised users must:
- keep login credentials confidential;
- use strong passwords;
- avoid password sharing;
- avoid using shared email accounts where possible;
- log out from shared or public devices;
- avoid accessing the dashboard from untrusted devices;
- notify EXICASH immediately of suspicious activity;
- ensure only authorised personnel access the dashboard;
- review user access from time to time;
- protect downloaded reports and transaction data.
EXICASH shall not be responsible for unauthorised access, data exposure, fraudulent activity, or losses caused by the merchant's failure to secure its own dashboard access, devices, staff accounts, passwords, email accounts, or internal systems.
9API Key, Token, and Credential Security
API keys, tokens, webhook secrets, production credentials, sandbox credentials, plugin credentials, and integration secrets are confidential and must be protected at all times.
Merchants must not:
- share API keys with unauthorised persons;
- publish API keys in public code repositories;
- expose API keys in frontend code;
- send API keys through unsecured channels;
- use production API keys in testing environments unnecessarily;
- reuse compromised credentials;
- allow former employees or contractors to retain access;
- use EXICASH credentials for any unauthorised business, merchant, website, or third party.
If an API key, token, webhook secret, or credential is leaked, exposed, stolen, compromised, or suspected to be compromised, the merchant must notify EXICASH immediately.
EXICASH may suspend, rotate, revoke, restrict, or disable API keys, tokens, webhook access, plugin access, or merchant access if we suspect compromise, misuse, prohibited activity, fraud, partner instruction, security risk, or breach of EXICASH's Terms.
The merchant shall bear responsibility for losses, claims, chargebacks, penalties, fraud, data exposure, prohibited activity, unauthorised transactions, partner action, or regulatory issues arising from leaked, compromised, exposed, or misused API keys or credentials caused by the merchant, its authorised users, employees, contractors, developers, service providers, systems, websites, or integrations.
10Sandbox and Production Environments
EXICASH may provide sandbox and production environments.
The sandbox environment is provided for testing and development purposes only. Sandbox data, responses, credentials, and results must not be treated as live payment processing, final settlement, or regulated transaction confirmation.
The production environment is used for live services and must be handled with higher security controls.
Merchants must ensure that:
- sandbox credentials are not confused with production credentials;
- production credentials are not used in public testing;
- test transactions are clearly separated from live transactions;
- production API keys are stored securely;
- only authorised developers and personnel access integration environments;
- testing does not disrupt EXICASH, licensed payment partners, or payment networks.
EXICASH may conduct test transactions, integration checks, or verification activities where necessary to test, verify, improve, inspect, or maintain platform functionality.
11Webhook and Callback Security
Merchants using webhooks, callbacks, or server-to-server notifications must secure their endpoints.
Merchants should:
- use secure HTTPS endpoints;
- validate webhook signatures or verification values where provided;
- restrict unnecessary public access;
- protect endpoints from abuse;
- log webhook activity securely;
- monitor failed webhook attempts;
- avoid exposing sensitive information in URLs;
- avoid relying solely on frontend redirects for transaction confirmation;
- reconcile transaction status using approved backend methods where applicable.
Merchants are responsible for losses, fulfilment errors, false payment confirmations, duplicate processing, refund issues, or reconciliation errors caused by insecure, misconfigured, unavailable, or compromised webhook endpoints.
12Plugin and Website Security
Merchants using EXICASH plugins for Shopify, WooCommerce, or custom websites must maintain the security of their own websites, plugins, hosting, themes, extensions, servers, and administrator accounts.
Merchants must:
- install plugins only from approved or trusted sources;
- keep plugins updated;
- keep website platforms updated;
- remove unused plugins and themes;
- secure administrator accounts;
- protect hosting access;
- use secure passwords;
- monitor suspicious website activity;
- prevent malware and unauthorised code injection;
- ensure their checkout flow is not modified to mislead consumers.
EXICASH is not responsible for losses, failed payments, false confirmations, data leakage, malware, website compromise, or transaction errors caused by the merchant's website, hosting provider, plugins, themes, developers, contractors, or third-party systems.
13Encryption and Secure Transmission
EXICASH may use encryption and secure transmission controls where appropriate to protect data transmitted through its platform.
Merchants must ensure that their own websites, applications, servers, API clients, webhook endpoints, and integrations use secure transmission methods where required.
Merchants must not transmit sensitive data, payment credentials, API keys, personal data, or confidential information over unsecured channels.
14Logging and Monitoring
EXICASH may maintain logs for security, technical, operational, compliance, fraud prevention, audit, and support purposes.
Logs may include:
- dashboard login records;
- API request and response metadata;
- webhook logs;
- IP addresses;
- device information;
- browser information;
- payment status changes;
- error logs;
- system events;
- user activity;
- fraud and risk indicators;
- security alerts;
- support actions.
Logs may be used to detect suspicious activity, investigate incidents, troubleshoot technical issues, support partner requests, protect platform integrity, and comply with legal or regulatory requirements.
Merchants must not tamper with, falsify, conceal, or misuse logs, reports, webhook records, transaction records, or technical information.
15Fraud Monitoring and Risk Controls
EXICASH may provide fraud monitoring tools, risk indicators, transaction review support, or suspicious activity alerts.
These tools are intended to support risk awareness and operational monitoring. They do not guarantee prevention of all fraud, chargebacks, scams, unauthorised transactions, prohibited activity, or consumer disputes.
EXICASH may monitor or review activity involving:
- unusual transaction patterns;
- repeated failed payment attempts;
- suspicious IP or device signals;
- API misuse;
- unusual refund or dispute patterns;
- prohibited business indicators;
- abnormal transaction volume;
- suspicious customer complaints;
- credential compromise indicators;
- activity reported by licensed payment partners.
EXICASH may suspend, restrict, review, or escalate activity where necessary for security, fraud prevention, partner compliance, or legal reasons.
16Security Incident Response
EXICASH maintains procedures to assess, investigate, contain, and respond to security incidents.
A security incident may include:
- unauthorised system access;
- data breach;
- credential compromise;
- API key leakage;
- malware;
- phishing attack;
- suspicious dashboard activity;
- unauthorised transaction activity;
- webhook compromise;
- platform abuse;
- attempted system intrusion;
- unauthorised disclosure of confidential information.
If EXICASH becomes aware of a security incident affecting EXICASH systems or data under EXICASH's control, we will take reasonable steps to investigate, contain, remediate, and document the incident.
Where required by applicable law, regulation, partner requirement, or contractual obligation, EXICASH may notify affected merchants, licensed payment partners, regulators, authorities, or affected individuals.
17Merchant Security Incident Notification
Merchants must notify EXICASH immediately if they become aware of any actual or suspected:
- dashboard account compromise;
- API key leak;
- webhook secret leak;
- production credential exposure;
- unauthorised access;
- malware infection;
- phishing incident;
- fraudulent transaction activity;
- compromised website or plugin;
- unauthorised use of payment links;
- consumer data breach;
- suspicious employee or contractor activity;
- use of EXICASH services for prohibited activity;
- incident that may affect EXICASH, consumers, licensed payment partners, or transaction data.
Reports should be sent to:
Email: support@exicash.com
The merchant must cooperate with EXICASH and, where applicable, licensed payment partners, regulators, or law enforcement agencies in investigating, containing, and resolving the incident.
18Vulnerability Reporting
If a merchant, developer, researcher, or third party discovers a suspected security vulnerability affecting EXICASH services, they should report it responsibly to:
Email: support@exicash.com
Reports should include sufficient details to help EXICASH verify and assess the issue.
The reporter must not:
- exploit the vulnerability;
- access, copy, modify, delete, or disclose data;
- disrupt EXICASH services;
- perform denial-of-service testing;
- test against live merchants or consumers without permission;
- publicly disclose the vulnerability before EXICASH has had reasonable time to investigate and remediate.
EXICASH may take appropriate action against unauthorised testing, exploitation, disclosure, or misuse.
19Third-Party and Licensed Partner Dependencies
EXICASH services may depend on third-party systems, including:
- licensed banks;
- registered merchant acquirers;
- payment gateways;
- card processors;
- card schemes;
- FPX infrastructure;
- DuitNow QR infrastructure;
- e-wallet providers;
- BNPL providers;
- payout or disbursement providers;
- cloud hosting providers;
- internet service providers;
- telecommunications providers;
- fraud monitoring providers;
- verification providers;
- software vendors;
- other technical service providers.
EXICASH does not control the security, uptime, availability, settlement process, risk review, or operational decisions of such third parties.
Service interruptions, transaction delays, failed callbacks, settlement report delays, unavailable payment methods, partner outages, or data delays may occur due to third-party systems outside EXICASH's reasonable control.
EXICASH is not responsible for losses or damages caused by third-party systems, payment partners, banks, payment networks, card schemes, e-wallet providers, BNPL providers, or other external providers outside EXICASH's reasonable control.
20Merchant System Responsibility
Merchants are responsible for securing their own systems and business environment.
This includes:
- websites;
- mobile apps;
- servers;
- hosting accounts;
- administrator accounts;
- staff email accounts;
- developer access;
- API clients;
- webhook endpoints;
- plugins;
- databases;
- routers and networks;
- devices;
- internal processes;
- consumer support channels.
Merchants should implement appropriate security controls based on their own business size, transaction volume, risk profile, and legal obligations.
Recommended controls include:
- strong passwords;
- multi-factor authentication where available;
- access restriction;
- regular access review;
- prompt removal of former staff access;
- secure coding practices;
- plugin updates;
- malware scanning;
- endpoint protection;
- secure backups;
- staff awareness;
- phishing prevention;
- monitoring of suspicious activity.
21Prohibited Security Conduct
Merchants must not:
- attempt to bypass EXICASH security controls;
- conduct unauthorised penetration testing;
- scan, probe, or attack EXICASH systems without permission;
- interfere with EXICASH services;
- misuse APIs or webhooks;
- use EXICASH services for malware, phishing, scams, or fraud;
- access data belonging to other merchants;
- share credentials with unauthorised persons;
- impersonate EXICASH, payment partners, merchants, or consumers;
- manipulate transaction status, receipts, reports, or webhook events;
- use EXICASH services for prohibited or illegal activities.
EXICASH may suspend, restrict, terminate, investigate, or report any activity that violates this section.
22Data Retention and Log Retention
EXICASH may retain security logs, API logs, webhook logs, transaction logs, onboarding records, support records, fraud signals, access records, and audit records for as long as necessary for service delivery, security, investigation, audit, legal, compliance, accounting, tax, partner, dispute, and fraud prevention purposes.
Certain records may be retained for up to seven (7) years or such longer period as may be required or permitted by law, partner requirements, audit requirements, tax requirements, dispute handling, regulatory requests, or legal proceedings.
Some technical logs may be retained for a shorter period unless required for investigation, security, compliance, or legal purposes.
23Business Continuity and Recovery
EXICASH may maintain business continuity and recovery practices designed to support service resilience and operational recovery.
However, EXICASH does not guarantee uninterrupted service, immediate recovery, continuous availability, or zero data loss in all circumstances.
Service availability may be affected by events beyond EXICASH's reasonable control, including cyberattacks, third-party outages, cloud provider issues, power failure, internet disruption, payment partner downtime, regulatory instructions, natural disasters, or force majeure events.
24Service Availability and No Absolute Security Guarantee
EXICASH aims to maintain secure and reliable services, but no technology platform, internet transmission, payment system, API, dashboard, plugin, or electronic storage method can be guaranteed to be completely secure, uninterrupted, or error-free.
EXICASH does not guarantee that:
- services will be available at all times;
- APIs will be uninterrupted;
- webhooks will always be delivered instantly;
- dashboards will always display real-time information;
- third-party payment systems will always be available;
- every security threat will be prevented;
- every fraudulent transaction will be detected;
- every credential compromise will be prevented.
Merchants should maintain their own monitoring, reconciliation, security, backup, and incident response procedures.
25Security Review and Updates
EXICASH may review and update this Security Statement from time to time to reflect changes in law, regulation, payment partner requirements, security practices, technical architecture, business operations, or risk environment.
The latest version may be published on www.exicash.com or made available through the dashboard, email, or other communication channels.
Continued use of EXICASH services after updates means that the merchant acknowledges the revised Security Statement.
26Contact
For security questions, suspected incidents, vulnerability reports, or security-related concerns, please contact:
EXICASH SDN BHD
Company Registration No.: 202601015752 (1677849-M)
Address: 16-19, Menara Mutiara Sentral, No. 2, Jalan Desa Aman 1, Cheras Business Centre, 56000 Kuala Lumpur, Malaysia
Email: support@exicash.com
Website: www.exicash.com