Security — the honest version
We do not claim certifications we do not have. This page describes what we actually do to keep your data and money safe during an etisalat quick recharge.
Card data stays off this site
The recharge form takes exactly three things: an Etisalat number, an email, and an amount. That is all. Card data is entered on the payment gateway that opens from the link we email you. topupcove has no card fields, no card widget, no card storage.
Transport
The site is served over HTTPS. HTTP requests are redirected to HTTPS. The form submits over the same secure channel.
Storage
Request records — number, email, amount, timestamp — are stored on a server in the UAE with restricted access. Backups are encrypted at rest. Retention is 24 months for accounting, then delete.
People
One manager handles requests. They log into the tool from a single machine with disk encryption and a hardware key. That is unglamorous but it is the whole story.
Reporting a problem
Please report anything that looks like a security issue to security@topupcove.com. Machine-readable contact is at /.well-known/security.txt. Please do not run automated scans that generate load — a short manual poke is fine.
What we do not do
We do not claim PCI DSS compliance because we do not process card data ourselves. We do not paste “bank-grade encryption” or “military-grade security” taglines. If a certification is not listed here, we do not hold it.
Last reviewed: 2026-07.