BossiPay is designed around HMAC signatures, server-side verification, idempotency, audit logs, transaction locking, webhook validation, and encrypted secrets.