Security and Privacy
Security is at the heart of what we do
Our security and compliance posture is critical to our business. PayStandards' Security and Privacy teams establish policies and controls, monitor compliance, and prove our posture to third-party auditors.
Governance
Four principles govern every control
Access is limited to only those with a legitimate business need and granted based on the principle of least privilege.
Security controls are implemented and layered according to the principle of defense-in-depth.
Security controls are applied consistently across all areas of the enterprise.
Controls mature iteratively, toward more effectiveness, more auditability, and less friction.
Security and compliance
PayStandards maintains a SOC 2 Type II attestation, certified and audited by Prescient Assurance and actively monitored by Vanta, alongside GDPR compliance, ISO 27001, ISO 42001, and EU AI Act compliance. Reports are available through our Trust Center.
Data protection
Data at rest
All datastores with customer data, in addition to S3 buckets, are encrypted at rest. Sensitive collections and tables also use row-level encryption.
Data in transit
PayStandards uses TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks, with HSTS enabled. Server TLS keys are managed by AWS via Application Load Balancers.
Secret management
Encryption keys are managed via AWS Key Management System (KMS), which stores key material in Hardware Security Modules (HSMs).
Product security
Vulnerability scanning at every key stage
- ✓Static analysis (SAST) testing at every pull request
- ✓Software composition analysis (SCA) for supply-chain vulnerabilities
- ✓Periodic network vulnerability scanning
- ✓Malicious dependency scanning to prevent malware
- ✓Dynamic analysis (DAST) of running applications
- ✓External attack surface management (EASM), continuously running
Corporate precautions
Endpoint protection
All corporate devices are equipped with mobile device management software and anti-malware protection. Endpoint security is monitored with 24/7/365 coverage.
Identity & access management
PayStandards secures identity and access via AWS, enforcing phishing-resistant authentication factors, using Cognito exclusively wherever possible, with role-based access and automatic deprovisioning upon termination.
Secure remote access
Remote access to internal resources runs through AWS's VPN platform, with malware-blocking DNS protecting employees on the open internet.
Security training
Comprehensive security training for all employees at onboarding and annually, mandatory live secure-coding onboarding for engineers, and regular threat briefings shared with staff.
Vendor security
A risk-based vendor program weighing integration with production environments, potential brand impact, and access to customer and corporate data.
Data privacy
Data privacy is a first-class priority. We strive to be trustworthy stewards of all sensitive data.
PayStandards evaluates updates to regulatory and emerging frameworks continuously to evolve our program. Read our Privacy Policy.
Looking to report a security concern? Please let us know at Contact Us.
Bring your security team's hardest questions.
Book a Demo. We'll complete your vendor assessment.
Enterprise pilots, scoped in your first call.
