Security

Built so you can trust it with your cash flow

MerchantLink never holds your money and never sees full card numbers. Here’s how we protect merchants, payers and the AI that works for them.

Payments

Money and card data stay with your processor

Funds settle directly

Payments are processed and settled by the processor or gateway you connect, straight to your account. MerchantLink never takes custody of funds.

Card data is tokenized

With a connected processor, card and bank details are entered into the processor’s own secure fields or hosted page and exchanged for a token, so full card numbers never reach MerchantLink’s servers.

Amounts set by the server

What a payer is charged is always calculated on the server from the invoice or link rules, never taken from the browser.

Platform

Defense in depth

Encrypted credentials

Processor API keys are verified with the provider, then encrypted with AES-256-GCM before storage.

Hashed secrets

Session tokens and API keys are stored only as SHA-256 hashes, and passwords with bcrypt.

Verified webhooks

Every processor webhook is signature-checked against that account’s own secret, and inbound SMS is verified with Twilio’s signature.

Card-testing protection

Public checkout is rate limited and risk-scored for velocity, repeated declines and micro-amounts before a processor is ever called.

Locked-down database

Row-level security blocks all public database API access; only the application’s own server role can read or write data.

Complete audit trail

An append-only event log records every invoice, payment, message, refund and approval, and who performed it.

Responsible AI

AI that asks before it acts

AI makes MerchantLink faster, but it never gets the final word on your customers or your money.

Human approval by default

AI-written reminders and replies wait in your Approvals queue. Autopilot is opt-in and limited to reminders. Refunds requested by AI agents always require approval.

Rules enforced in code

SMS consent, quiet hours, amount limits and payable amounts are checked in code after the model responds. The model can’t override them.

Least privilege for agents

API keys carry explicit scopes, optional amount ceilings and an approval requirement. Revoke a key instantly from the dashboard.

Prompt-injection aware

The payer assistant treats customer messages as questions, not instructions. It can’t change amounts or terms, and never asks for card or bank details.

Messaging

Respectful by design

Customers are only texted after the merchant confirms they agreed to receive texts, and that consent is recorded with a timestamp. Replying STOP opts a customer out immediately; START opts them back in.

Automated texts are never sent during quiet hours in the merchant’s time zone. Reminder copy is written to be courteous and specific, and the AI is instructed never to threaten, shame, or mention collections, credit reporting or legal action.

Send your first payment link today

Every account starts with a built-in sandbox, so you can create invoices, send links and take test payments before you connect a processor.