256-Bit TLS 1.3 Transport Security
All API communications between your device, Eligify servers, and partner banking networks are encrypted using military-grade TLS 1.3 protocols.
HMAC-SHA256 Request Verification
Financial transactions and BaaS API calls are signed with SHA256 hashes and timestamped nonces to prevent tampering or replay attacks.
Customer Security Safeguards
- • Eligify employees will NEVER ask for your OTP, PIN, Card CVV, or Online Password over phone, email, or SMS.
- • Never share screen-sharing app access (e.g., AnyDesk, TeamViewer) with unknown caller representatives.
- • Report lost cards or suspicious transfers instantly through our emergency helpline.
Responsible Disclosure & Vulnerability Reporting
We welcome security researchers to inspect our platform responsibly. If you discover a vulnerability or security bug, please email us with technical reproduction steps.
