This page exists alongside our Security page, not instead of it — Security covers the technical detail; this page is the at-a-glance status of everything a business evaluating Paynancial would want to check before trusting it with real transactions, including the parts that aren't fully documented yet.
Trust, At a Glance
"Verified" means confirmed and already described in detail on our Security page. "Verify" means it needs a formal confirmation — a certificate, a signed document, a specific regulatory status — before we're willing to state it here as fact. A "Verify" label is not a claim that something is missing; it's a statement that we haven't published a claim about it yet.
Security Foundations
All data in transit is encrypted with TLS 1.2 or higher; sensitive data at rest, including KYC documents and bank details, uses AES-256. Card data is tokenized on receipt and never stored raw on our application servers. Systems handling cardholder data run in a separate, access-restricted environment with regular vulnerability scanning. Internal access follows least privilege, is logged, and requires multi-factor authentication for privileged actions. Transactions pass through real-time risk scoring before funds move.
Full detail on each of these — plus how to report a vulnerability — lives on the Security page, which this Trust Center doesn't duplicate.
Privacy
What data we collect, why, and how long we keep it is set out in full in our Privacy Policy — this section exists so Privacy has a visible home in the Trust Center rather than only being reachable from the legal footer.
Business Continuity & Disaster Recovery
Our production infrastructure already runs in access-controlled cloud environments with network firewalls and DDoS mitigation in front of every public endpoint, and deployments are version-controlled and auditable — see Security Foundations above. A formal, published business continuity and disaster recovery plan — covering specific recovery time objectives and failover procedures — is not yet documented on this page.
AI Governance
The operating principle behind every AI feature Paynancial offers is described in full on the Agentic AI page: permissions define what an agent can do, policy limits cap how much, human oversight reviews anything above a threshold, every action is authenticated to a specific key or session, and every action is logged against the rule that authorized it.
What's confirmed today: this principle governs how our AI & Intelligence products (AI Fraud Detection, AI Reconciliation, AI Financial Assistant, AI Cash-Flow Intelligence, AI Revenue Forecasting) are designed to operate. What's not yet published: a standalone, formally reviewed AI governance policy document, distinct from the product-level description above.
Human Oversight
No AI capability on this site is positioned as removing a business's ability to require human approval. Spending limits, beneficiary allow-lists and approval thresholds are configured by the business using the platform, not fixed by Paynancial — a business decides how much of a workflow an agent handles unattended, and can tighten or loosen that at any time.
Auditability
Every write action against the API — a payment, a payout, a refund — is tied to the specific API key or session that made the request, and idempotency keys mean a retried request is recognized rather than treated as a new action. Webhooks provide a real-time, timestamped record of every state change, which is the same data an audit trail draws from.
How We Label Claims on This Page
| Label | What it means |
|---|---|
| Verified | Confirmed practice, described in detail elsewhere on this site (typically the Security page). |
| In Progress | Actively being built or documented — used only once we can say that truthfully. |
| Planned | On the roadmap with a committed timeline — used only once one exists. |
| Verify | Not yet confirmed internally. We'd rather show this label than guess. |
If you need a specific answer for a procurement or compliance review that isn't covered above, contact our team directly rather than relying on this page alone.