Payment boundaries
Customer payment authorization remains with the relevant payment provider, and RoamerWave never asks customers to enter their wallet PIN into RoamerWave.
Merchant and workspace isolation
The product architecture uses workspace-scoped ownership and authorization so merchant records and provider references resolve within their intended boundary.
Identity, data and payment integrity
RoamerWave uses managed authentication and stronger controls for privileged actions. The product minimizes sensitive payment data in URLs and ordinary logs, and is designed around immutable seller, amount, currency and destination binding, stable command identities and customer-authorised provider flows.
Evidence-backed states and resilience
Payment confirmation, reconciliation and settlement remain separate facts; unresolved outcomes are not converted into convenient results. Engineering controls are designed around reviewed changes, secret protection, durable work, auditable records, monitoring and recovery.
Responsible disclosure
Report a security issue to support@roamerwave.com with enough detail to reproduce it safely. Do not access others' data, disrupt services or disclose it publicly before we can investigate. RoamerWave does not offer a bug bounty.
Service status
Current service status is available at status.roamerwave.com.