Help Section
Legal

Security Requirements

 

Version: 1.2

Version: 1.2

Effective Date: 2026-06-10


1. Purpose

These Security Requirements ("Requirements") form part of the Kwik Merchant Agreement.

Their purpose is to establish the minimum security standards required of all Merchants using the Services, and to support Kwik's compliance with the security safeguards condition for lawful processing under section 19 of POPIA, as well as Kwik's obligations to its acquiring and sponsoring banks and the applicable Card Schemes.

Failure to comply with these Requirements may result in suspension or termination of the Services.

These Requirements should be read together with the Information Security Policy and the Data Processing Addendum.


2. Scope

These Requirements apply to:

  • Merchant Accounts;
  • authorised users;
  • APIs;
  • SDKs;
  • payment integrations;
  • hosted checkout implementations;
  • embedded checkout implementations;
  • payment links;
  • webhook integrations;
  • mobile applications;
  • websites;
  • servers; and
  • any system connected to the Services.

3. Merchant Security Responsibilities

The Merchant shall maintain commercially reasonable administrative, technical and organisational measures designed to protect:

  • Customer information;
  • Personal Information;
  • authentication credentials;
  • API credentials;
  • payment data;
  • transaction information; and
  • systems connected to the Services.

The Merchant remains responsible for the security of its own systems and infrastructure.


4. Merchant Account Security

The Merchant shall:

  • maintain accurate user records;
  • promptly remove users who no longer require access;
  • restrict administrative access;
  • regularly review user permissions;
  • immediately report suspected account compromise; and
  • ensure each authorised user has an individual account.

Shared user accounts are strongly discouraged unless expressly supported by the Services.


5. Authentication

Where supported by Kwik, the Merchant shall enable Multi-Factor Authentication (MFA) for administrative users.

Passwords shall:

  • be unique;
  • not be reused across unrelated services;
  • not be shared;
  • not be stored in plain text;
  • be changed immediately if compromise is suspected.

The Merchant shall not attempt to bypass authentication controls implemented by Kwik.


6. API Security

API credentials are confidential.

The Merchant shall:

  • securely store API credentials;
  • prevent unauthorised disclosure;
  • rotate credentials where compromise is suspected;
  • immediately revoke compromised credentials;
  • use HTTPS for all API communication;
  • validate responses received from Kwik; and
  • implement appropriate timeout and retry logic.

API credentials shall never be:

  • published publicly;
  • embedded in client-side applications;
  • committed to public source repositories; or
  • shared with unauthorised persons.

7. Webhook Security

Where webhooks are used, the Merchant shall:

  • validate webhook signatures;
  • use HTTPS endpoints;
  • verify request authenticity;
  • securely store webhook secrets;
  • prevent replay attacks where reasonably possible;
  • log webhook events;
  • implement idempotency where appropriate; and
  • monitor webhook failures.

Failure to validate webhook signatures may expose the Merchant to fraudulent requests.


8. Infrastructure Security

The Merchant shall implement commercially reasonable security measures designed to protect systems connected to the Services.

These measures should include, where appropriate:

  • operating system updates;
  • security patching;
  • firewall protection;
  • endpoint protection;
  • malware detection;
  • network segmentation;
  • encrypted storage;
  • encrypted communications;
  • secure backups; and
  • disaster recovery procedures.

9. Secure Software Development

Where the Merchant develops software integrating with the Services, the Merchant shall implement secure software development practices.

This includes, where appropriate:

  • secure coding;
  • code review;
  • dependency management;
  • vulnerability scanning;
  • security testing;
  • input validation;
  • output encoding;
  • authentication controls;
  • access controls; and
  • secure deployment procedures.

10. Payment Security

The Merchant shall not:

  • intercept payment credentials;
  • modify hosted payment pages;
  • interfere with payment authentication;
  • attempt to decrypt payment tokens;
  • store prohibited payment information; or
  • otherwise compromise payment security.

Where Kwik provides hosted payment pages, embedded checkout or tokenisation, the Merchant shall use those mechanisms in accordance with Kwik's documentation.


11. PCI DSS

Where applicable, the Merchant is responsible for maintaining the level of PCI DSS compliance required by its integration method and transaction volume, as determined by the applicable Card Schemes and Kwik's acquiring bank from time to time.

The Merchant shall not:

  • store sensitive authentication data after authorisation;
  • retain CVV, CVC or CID values after authorisation;
  • retain PIN data;
  • retain magnetic stripe data; or
  • otherwise process cardholder data contrary to PCI DSS.

Where requested by Kwik or required by Kwik's acquiring bank or the applicable Card Schemes, the Merchant shall complete and submit a PCI DSS Self-Assessment Questionnaire (or other validation of compliance) appropriate to its integration method, and any supporting Attestation of Compliance, within the timeframe specified by Kwik.

The Merchant acknowledges that use of Kwik's hosted payment solutions may reduce, but does not eliminate, its PCI DSS obligations.

Where a fine, penalty, or assessment is imposed on Kwik or its acquiring or sponsoring bank by a Card Scheme as a result of the Merchant's, or the Merchant's third-party processor's, failure to comply with PCI DSS, the Merchant shall reimburse Kwik for that fine, penalty, or assessment in accordance with Section 30 (Indemnities) of the Merchant Agreement.


12. Third-Party Software

The Merchant remains responsible for:

  • plugins;
  • ecommerce platforms;
  • ERP integrations;
  • CRM integrations;
  • accounting software;
  • middleware;
  • custom software; and
  • any third-party application connected to the Services.

Kwik is not responsible for vulnerabilities within third-party software used by the Merchant.


13. Logging and Monitoring

The Merchant should maintain sufficient logging to:

  • investigate fraud;
  • investigate disputes;
  • investigate security incidents;
  • identify unauthorised access;
  • investigate payment failures; and
  • comply with Applicable Law.

Logs should be protected against unauthorised modification.


14. Security Incidents

The Merchant shall notify Kwik without undue delay, and in any event within twenty-four (24) hours, after becoming aware of:

  • credential compromise;
  • API compromise;
  • webhook compromise;
  • data breaches;
  • ransomware;
  • malware affecting payment systems;
  • unauthorised access;
  • fraud involving the Services; or
  • any other security incident reasonably likely to affect the Services.

This timeframe is consistent with the notification timeframe set out in Section 22 of the Merchant Agreement and the Data Processing Addendum, and reflects equivalent notification obligations owed by Kwik to its sponsoring and acquiring banks.


15. Security Investigations

The Merchant shall cooperate fully with security investigations conducted by Kwik.

Kwik may require:

  • security questionnaires;
  • incident reports;
  • forensic reports;
  • vulnerability assessments;
  • penetration testing summaries;
  • remediation plans; or
  • other information reasonably necessary to assess ongoing risk.

16. Right to Protect the Platform

Where Kwik reasonably believes the security of the Services is at risk, Kwik may immediately:

  • rotate credentials;
  • suspend API access;
  • disable user accounts;
  • suspend payment methods;
  • suspend settlements;
  • suspend payouts;
  • require password resets;
  • require additional authentication;
  • require security remediation;
  • temporarily suspend the Merchant Account; or
  • terminate the Merchant Agreement.

Kwik shall not be liable for losses arising from protective measures reasonably implemented in good faith.


17. Compliance Verification

Kwik may request reasonable evidence demonstrating compliance with these Requirements.

Evidence may include:

  • completed security questionnaires;
  • PCI DSS Self-Assessment Questionnaires and Attestations of Compliance;
  • penetration testing summaries;
  • vulnerability management reports;
  • independent certifications;
  • internal security policies; or
  • other documentation reasonably required by Kwik.

Failure to provide requested information within a reasonable timeframe may result in suspension of the Services.


18. Policy Updates

Kwik may amend these Security Requirements from time to time to reflect:

  • emerging security threats;
  • changes in Applicable Law;
  • payment network requirements;
  • banking requirements;
  • technological developments;
  • industry standards; or
  • operational improvements.

The latest version will always be published at:

/legal/security-requirements

Continued use of the Services after the effective date of an updated version constitutes acceptance of the revised Requirements where permitted by Applicable Law.


19. Contact

Questions relating to these Requirements may be directed to:

Information Security Team

Email: security@kwik.co.za