Governance and Risk Management Policy

Attested

This Information Security Program (ISP) has been formally documented and approved by Payzario management. It serves as the foundation of our organization's commitment to security.

Company: Payzario Inc. | Effective Date: April 2025 | Version: 1.0

1. Purpose

This Governance and Risk Management policy establishes Payzario's formal Information Security Program (ISP). The ISP serves as the foundation for our information security posture, outlining the organization's commitment to protecting the confidentiality, integrity, and availability of all information assets — including customer data, financial records, and internal systems.

2. Information Security Program (ISP) — Five Core Requirements

1. Defined Objectives

Payzario's information security program is designed to achieve the following objectives:

  • Protect the confidentiality, integrity, and availability of customer and financial data.
  • Ensure compliance with applicable regulations and third-party requirements (e.g., Plaid, Stripe, financial data standards).
  • Minimize the risk of data breaches, unauthorized access, and system disruption.
  • Maintain customer trust through transparent, responsible data handling.
  • Continuously improve security posture through regular reviews and audits.

2. Established Accountability

Security responsibilities are clearly assigned across the organization:

  • Executive Leadership: Accountable for approving the ISP and allocating resources for security initiatives.
  • Admin / Security Lead: Responsible for implementing, maintaining, and enforcing security policies day-to-day.
  • All Team Members: Required to comply with security policies, complete relevant training, and report incidents promptly.
  • Third-Party Vendors: Held to Payzario's security standards as a condition of engagement (e.g., Plaid, Stripe).

3. Established Scope

This ISP applies to:

  • All Payzario systems, applications, and infrastructure (including Base44, cloud hosting, and domain services).
  • All customer-facing services including the Payzario web app, bill management, and Pay Later features.
  • All third-party integrations that handle or access customer or financial data (Stripe, Plaid, Resend).
  • All employees, contractors, and vendors with access to any Payzario system or data.
  • All data at rest and in transit, including financial records, Plaid-sourced bank data, and user PII.

4. Management Approval

This ISP has been reviewed and approved by individuals with management responsibilities at Payzario Inc. Management approval confirms:

  • The organization's formal commitment to information security.
  • Authorization to enforce all policies contained within this program.
  • Allocation of appropriate resources (time, tools, personnel) to support security operations.
  • Accountability at the leadership level for maintaining the program.

Approved by: Payzario Inc. Executive Leadership

Effective Date: April 2025

5. Kept Up to Date

The ISP and all related policies are maintained on an ongoing basis:

  • Formal review is conducted annually or upon any significant change to systems, regulations, or business operations.
  • Policies are updated immediately following any security incident or audit finding.
  • All updates are version-controlled and dated.
  • Team members are notified of material changes to policies that affect their responsibilities.

3. Risk Management Framework

Payzario maintains an ongoing risk management process to identify, assess, and mitigate information security risks:

  • Risk Identification: Threats and vulnerabilities are identified through periodic reviews, vendor assessments, and monitoring of the threat landscape.
  • Risk Assessment: Each identified risk is evaluated based on likelihood and potential impact to the business and customers.
  • Risk Treatment: Risks are mitigated through controls, accepted with documented rationale, or transferred (e.g., via cyber insurance or vendor SLAs).
  • Risk Monitoring: Residual risks are tracked and reviewed regularly, with treatment plans updated as needed.

4. Compliance Obligations

Payzario's security program is designed to meet or exceed the requirements of:

  • Plaid's developer and production API security requirements
  • Stripe's data handling and PCI-DSS compliance obligations (as a Stripe user)
  • Applicable U.S. state and federal data privacy laws
  • General industry best practices for fintech and SaaS platforms

5. Policy Hierarchy

This ISP is the top-level governance document. It is supported by the following specific policies:

  • Information Security Policy
  • Access Control Policy
  • Data Retention & Deletion Policy
  • Vulnerability & Patch Management Policy
  • MFA Policy
  • Employee Access Review Policy
  • Identity & Access Management Policy
  • Privacy Policy (public-facing)

6. Policy Review

This policy is reviewed annually, or upon significant changes to the organization, systems, or regulatory environment. The Admin is responsible for scheduling and documenting each review.

Owner: Payzario Inc. | Contact: support@payzario.com