Payment protection for online stores

Take payments behind a shield.

Zivrix lets your shoppers pay with PayPal and Stripe inside an isolated, server-verified layer — so card details and gateway credentials never touch your website, and every order is confirmed with the provider before you ship.

Log in to your dashboard → PayPal & Stripe · one integration

Why Zivrix

Less risk on your checkout, more trust at the till

The payment UI runs in a secured iframe served by Zivrix. Your page collects an order; the money moves inside the shield.

Card data never touches your site

Payment fields live in an isolated iframe. Your pages — and your logs — never see card numbers or PSP secrets, keeping your PCI surface small.

Every payment is server-verified

Before you fulfil an order, your backend confirms it with Zivrix. Amounts are checked to the cent and each payment is single-use — no replays, no tampering.

Works where you sell

A WooCommerce plugin for WordPress stores, or a lightweight browser SDK for any custom, Next.js, React or Vue checkout.

How it works

Live in three steps

Add your gateways

Connect PayPal and/or Stripe in the dashboard. Credentials are encrypted at rest and never sent to the browser.

Drop in the plugin or SDK

Install the WooCommerce plugin, or add the SDK script to your store. The payment UI renders in a secured iframe, pre-warmed so it appears instantly.

Verify, then fulfil

Your backend verifies each payment with Zivrix and only then marks the order paid. Reconcile anytime with the lookup API.

Built for operators

One integration, two gatewaysPayPal and Stripe side by side, with health checks and failover.
Seller Protection readyLine items, shipping address and tracking passed through to PayPal.
Refunds & reconciliationIssue refunds and look up any transaction by your own order id.
Fast checkoutDeferred-intent Stripe and pre-warmed iframes — the pay UI shows in a blink.

What's inside

A complete checkout shield

Isolated checkout iframe

Payment UIs are served from the shield host and talk to your page only through origin-checked messages.

Single-use verification

A payment can complete exactly one order; reuse and amount mismatches are rejected.

Gateway health & rotation

Credentials are probed in the background; unhealthy gateways step aside automatically.

Signed server-to-server API

Verify, refund, tracking and lookup calls are HMAC-signed and rate-limited per shield.

Webhooks & lookup

Signed payment webhooks, plus a read-only lookup so tab-close orders still reconcile.

Validate before pay

Finalise the amount and order id at the moment the shopper clicks — no early commitment.

Security by default

The sensitive parts stay sensitive

Zivrix is built so a leaked token is useless on its own and card data never reaches your servers.

Encrypted credentials

Gateway keys are encrypted at rest and never exposed to the browser.

Origin allowlisting

Only your registered store domains can talk to the shield and receive payment events.

Server-side truth

Browser events are UI signals only — order state changes on verified server confirmation.

Pricing

Plans that scale with your checkout

You keep your own PayPal and Stripe accounts — Zivrix is the protection layer on top. Tell us your volume and stack and we'll tailor a plan.

Starter

For a single store going live with protected checkout.

Let's talktailored to your volume

  • 1 shield (store)
  • PayPal & Stripe gateways
  • WooCommerce plugin or SDK
  • Server-side verification
  • Email support
Contact sales

Scale

For high-volume merchants and platforms.

Let's talkcustom terms

  • Everything in Growth
  • Higher rate limits & throughput
  • Custom webhooks & integrations
  • Onboarding & migration help
  • SLA & dedicated contact
Contact sales

All plans include the isolated checkout iframe, encrypted credentials and signed server-to-server APIs. Sandbox testing is free.

FAQ

Frequently asked questions

Does card data ever touch my website?

No. PayPal and Stripe payment fields render inside an isolated iframe served by Zivrix. Your pages and server logs never see card numbers or gateway secrets, which keeps your PCI scope small.

Do I keep my own PayPal and Stripe accounts?

Yes. Zivrix is bring-your-own-keys: you connect your own PayPal and Stripe credentials, the money settles to your accounts, and Zivrix protects and verifies the flow. Credentials are encrypted at rest and never exposed to the browser.

Which platforms and gateways are supported?

A WooCommerce plugin for WordPress stores, or a lightweight browser SDK for any custom, Next.js, React or Vue checkout. Both PayPal and Stripe work side by side, with health checks and failover.

How are payments verified and refunded?

Your backend confirms each payment with Zivrix before you fulfil the order — amounts are checked to the cent and each payment is single-use. Refunds and transaction lookups are available from the dashboard and a signed server-to-server API.

Can I test before going live?

Yes. Add sandbox PayPal / Stripe test credentials to a test shield and run the full checkout on staging before switching to live keys. Sandbox testing is free.

How do I get started and what does it cost?

Pricing is tailored to your volume and stack — contact sales for a quote. If you already have an account, just log in, add a gateway, and connect your store.

Ready to protect your checkout?

Sign in to your dashboard to add a gateway and connect your store.

Log in →