Full platform access · every action here is logged and cannot be erasedChanges are audit logged

Payment providers

How customers pay, what it costs, and when the money lands.

Enabled
5
Mobile money
3
Without pre-auth
1
financial risk
In sandbox
0

Card data never touches this platform. The acquirer returns a token; we store the token and the last four digits, nothing else. No PAN, no CVV, not in the database and not in logs. Credentials below are write-only - once saved, a secret can be rotated but never read back, not even here.

eZ Cash (Dialog)Mobile moneylive

Aggregator: PayHere. STK push + callback.

Fee: 1.8%Settlement: T+1Pre-auth: Supported
FriMiMobile moneyliveno pre-auth

No true pre-auth - full-amount debit then adjust. See risk register.

Fee: 2.0%Settlement: T+1Pre-auth: Not supported
Known risk. Without pre-auth the customer is debited the full estimate up front and refunded the difference. On an interrupted session that means a real refund cycle, not a released hold - slower for the customer and more reconciliation work for finance. This is the root cause of the open FriMi exceptions.
mCashMobile moneylive

Aggregator: PayHere.

Fee: 1.9%Settlement: T+1Pre-auth: Supported
Visa / MastercardCardlive

Acquirer: Commercial Bank. 3-D Secure enforced. Tokenised - no PAN stored.

Fee: 2.6% + LKR 200Settlement: T+2Pre-auth: Supported
Platform walletWalletlive

Stored balance. Ledger-backed.

Fee: 0%Settlement: InternalPre-auth: Supported

Wallet settings

Stored balance - a liability, treat it like one

LKR
LKR
LKR
LKR
Allow wallet top-up
Allow auto top-up

Needs a saved payment token and explicit consent.

Allow withdrawal to mobile money

Adds AML obligations - legal review first.

Wallet balance expires after inactivity

Off. Expiring customer money is a policy decision, not a technical one.

Current wallet liabilityLKR 96,400

Refunds & voids

Who can move money back

Refunds require finance approvallocked

Operators and support can request; only finance approves. This is a spec rule, not a preference.

Auto-refund failed sessions under threshold

Would bypass the approval rule above. Leave off.

Allow partial refunds
Notify customer on refund
days
LKR

Auto-approve is set to zero, which means never. Raising it creates a path to move customer money without a second pair of eyes - if you do it, keep it small and watch the audit log.