BETA PayKonek is currently in beta. Features and availability may change as we improve the platform.
Share feedback

TRUST CENTER

Security and privacy materials are being prepared

PayKonek Digital Payments Inc. is preparing its final security and privacy documentation. This page is a working trust-center template and should not be treated as a statement of verified controls, certifications, or final policy commitments.

DRAFT CONTROL PRINCIPLES

Areas that should be addressed in the final security program

The final Trust Center should describe only controls that have been implemented, reviewed, approved, and verified for the applicable PayKonek environment.

Data protection

Verify the safeguards used to protect information in transit, at rest, and throughout its lifecycle before describing them publicly.

Access control

Document verified account, authentication, role, least-privilege, and administrative-review controls where implemented.

Monitoring and visibility

Confirm monitoring, logging, alerting, operational review, and investigation capabilities in the deployed environment.

Governance and accountability

Maintain approved policies, procedures, records, ownership, and response processes for responsible operations.

CONTROL AREAS

Items to verify before final publication

Each statement in the final security documentation should be checked against the deployed environment, approved policies, partner obligations, operational procedures, and applicable regulatory requirements.

Encryption and secure transport

Verification required

Confirm the actual TLS, encryption-at-rest, key-management, storage, certificate, and transport controls before making public statements.

Identity and permissions

Verification required

Confirm how system and product access are authenticated, approved, reviewed, limited by role, and removed when no longer required.

Logging and auditability

Verification required

Confirm records maintained for authentication, configuration changes, payment activity, support investigations, and operational review.

Infrastructure separation

Verification required

Describe production, staging, development, backup, recovery, and environment-separation practices only where they exist in the deployed environment.

Change management

Verification required

Confirm the processes used for changes, dependencies, releases, testing, approvals, rollback, and operational-risk review.

Incident readiness

Verification required

Confirm processes for triage, containment, investigation, remediation, notification, evidence handling, and post-incident improvement.

Incident response framework

The final incident-response process should be documented, tested, approved, and aligned with PayKonek’s deployed systems, customer commitments, payment partners, legal obligations, and applicable notification requirements.

1
Assess the report or alert and determine the initial scope, urgency, ownership, and affected systems.
2
Contain affected systems, access, credentials, integrations, or workflows where necessary and appropriate.
3
Investigate the cause, impact, affected information, transaction activity, partner dependencies, and operational consequences.
4
Remediate the issue, validate recovery, document findings, and strengthen relevant controls or procedures.
5
Notify customers, partners, regulators, authorities, or other parties when appropriate, required, and approved through the applicable process.

RESPONSIBLE DISCLOSURE

Found a potential security issue?

Please report suspected vulnerabilities privately so the team can review the report. Do not include passwords, one-time passwords, secret keys, private keys, full card numbers, or unnecessary personal information in your message.

Need more information?

Organizations performing security, privacy, vendor, or partnership reviews can contact PayKonek to discuss available information, requirements, and the status of relevant documentation.

Security and privacy documentation is under preparation. Final materials will be published only after appropriate technical, operational, legal, and management review.