The questions procurement asks.
Certifications, controls and the way we handle data, stated plainly rather than buried in a security page nobody finishes.
Payment security
PCI MPoC
Mobile payments on commercial off-the-shelf devices, certified.
PCI CPoC
Contactless payments on COTS devices, certified.
EMV L2 and L3
Kernel and acquirer-level certification for retail EMV.
No key injection
Devices provision in the field rather than through a key injection facility.
How the platform is governed
Tenant isolation
Every tenant scoped at the data layer, not by a filter someone remembered to apply.
Role-based access
Granular permission levels, with entitlements set per tenant and per module.
Immutable audit log
Every consequential action recorded and queryable, retained for review.
AML, OFAC and KYC
Screening at onboarding and continuously afterwards, with evidence retained.
Encryption
Data encrypted in transit and at rest, with key material handled outside the application.
Human gate on AI
Model output is staged for review and never drives a live figure unpromoted.