Security
Security Statement
PayGap's security model must cover the customer account, internal systems and every third party involved in fiat funding, custody, conversion, blockchain settlement and payout.
01Our responsibilities
Universo is responsible for protecting the PayGap app and information within its responsibility. Financial providers are responsible for the systems and services they operate. We will coordinate security issues that cross that boundary.
We will maintain safeguards appropriate to the information and risks involved, including controlled access, secure development and change handling, protection of service credentials, and procedures for investigating incidents. Details that could expose systems to misuse will not be published.
No online system can eliminate every risk. That limitation does not reduce our obligation to use appropriate care or meet applicable security duties.
02Protecting your access
Use a device you control, keep it updated and use the authentication options made available in the app. Avoid shared devices for financial activity. Check that messages and links come from an official channel before entering information.
Do not share passwords, one-time codes, private keys or recovery phrases with anyone claiming to be support. We will not ask you to transfer money to a personal account to "secure", "unlock" or recover funds.
03Suspected incidents
If a device is lost, access is compromised or a payment looks unfamiliar, use the Contact form promptly. Give the affected profile or payment reference and a safe way to reach you. Avoid sending sensitive documents unless support provides an appropriate channel.
We will investigate, take proportionate protective action and coordinate with relevant providers. We will notify affected people and authorities where required by applicable law. We will explain recovery steps when it is safe and lawful to do so.
Questions about information rights should use the Privacy Notice.
04How the website protects the support destination
The website sends contact and complaint messages to a same-site server endpoint. The recipient is stored as a server secret rather than a visible address or public form destination. The handler checks form fields and does not pass a provider’s response or error text back to the visitor. These controls protect the delivery configuration; they are not a claim that every message is risk-free or that the wider app has a security certification.
If submission fails, return to the form and retain your message before trying again. Do not include credentials or identity documents in an attempt to troubleshoot delivery.
PayGap · Technology that connects
See how the settlement model fits together.