Some of these will occasionally get in your way. Each one is here because its absence causes a specific harm, and it is worth knowing which.

A payer’s number is never supplied by anyone else

Not by you, not by our API, not by an integration. The customer types it on the page and proves it with a code. Without this rule, Paynecta becomes a way to send M-Pesa prompts to people who never asked for one. Safaricom treats those as unsolicited pushes and flags the shortcode they came from, which would be yours.

We never ask you for a code

Nobody from Paynecta will call, message or email you asking for a code, for any reason. A code proves you are holding your phone, so reading one out hands that proof to somebody else. Anyone asking for one is trying to take your account or your money, whoever they say they are. The same is true for your customers: a code sent to a payer is theirs alone. See Codes and messages.

Attempts are capped

Per payer, per page, per business and per address. Somebody trying numbers in sequence runs out long before it becomes a campaign.

Where money goes is guarded

Changing a settlement destination is the single most valuable thing an attacker who reached your account could do. So it needs a code sent to the address on the account, and every change is recorded with who made it. We never show a full bank account number back. Entered once, and after that you see the bank and the name on the account.

The verified name is what customers see

Your payment page shows the name from your verification documents, not the name you typed into a form. Somebody deciding whether a page is really you should be looking at a name somebody checked. Reserved names exist for the same reason: nobody can take a payment address that impersonates a bank, a regulator, or a well-known service.

Nothing is settled on a guess

An answer we cannot read is not an outcome. A payment stays open rather than being closed on it, and we keep asking. See How a payment works.

Callbacks are checked

Safaricom signs nothing. So a callback is accepted only from Safaricom’s own addresses, at a path nobody can guess, and one claiming an amount nobody asked for is refused and recorded rather than acted on.

Your balance can always be explained

Nothing sets a balance directly. It is what its entries add up to, entries are never edited or deleted, and a mistake is corrected by writing the opposite entry. Each entry is chained to the one before it, so a missing or altered entry is visible rather than quietly shifting a total. A wallet whose balance can be changed without a trace is one nobody can audit, including us.