Security Policy
The technical and organisational controls protecting the platform, your credentials and your transaction data.
Last updated: [[DATE]]
Draft — not yet legal advice
This document is a working draft written to give a qualified lawyer a strong starting point. Every highlighted value is a fact only NexliPay can supply — entity name, jurisdiction, registration and licence numbers, addresses, named contacts. Do not publish this page until a solicitor licensed in your operating jurisdiction has reviewed it and every placeholder is filled with a true value.
01Access to your accounts
NexliPay connects to your processors through their official APIs using scoped credentials. We request the narrowest permission set that will support routing and reconciliation, we never ask for your processor dashboard password, and you can revoke our access from inside your own processor account at any time without contacting us.
Credentials are encrypted at rest with KMS / ENCRYPTION APPROACH and are never written to logs, support tickets or analytics.
02Encryption
- TLS 1.2 or higher for all data in transit, with HSTS enforced.
- AES-256 for data at rest, including database volumes and backups.
- Key management through KEY MANAGEMENT SERVICE with rotation every ROTATION PERIOD.
03Platform controls
- Least-privilege access, granted by role and reviewed ACCESS REVIEW FREQUENCY.
- Mandatory multi-factor authentication for all staff and all administrative access.
- Production access is logged, time-bound and requires a second approver.
- Separate development, staging and production environments; no production data in lower environments.
- Immutable audit logging of routing decisions, configuration changes and administrative actions.
- Automated dependency and container scanning in CI, with PATCH SLA for critical vulnerabilities.
04Card data
We do not store primary account numbers or CVV values. Card data stays inside your processors’ PCI DSS environments and we operate on tokenised references and metadata. This keeps our PCI scope deliberately small, which is itself a security control.
05Resilience
The platform runs across NUMBER availability zones in REGION with automated failover. Backups are taken BACKUP FREQUENCY, encrypted, and restore-tested RESTORE TEST FREQUENCY. Our recovery objectives are RPO RPO and RTO RTO.
06Testing and assurance
Independent penetration testing is carried out PENTEST FREQUENCY by PENTEST PROVIDER. Our current certifications are CERTIFICATIONS — e.g. SOC 2 Type II, ISO 27001, and a summary report is available under NDA on request.
07Reporting a vulnerability
Send findings to security@nexlipay.com, including steps to reproduce. We acknowledge within ACK SLA and aim to remediate critical issues within REMEDIATION SLA.
We will not pursue legal action against researchers who act in good faith, stay within the scope of their own test accounts, avoid privacy violations and service degradation, and give us reasonable time to fix an issue before disclosing it.
08Incident response
Incidents are triaged by severity and led by INCIDENT LEAD ROLE. Where a personal data breach is likely to result in a risk to individuals, we notify SUPERVISORY AUTHORITY within 72 hours and affected customers without undue delay. Post-incident reviews are shared with affected customers.
Questions?
Write to legal@nexlipay.com or use the contact page.