Information Security Policy
Company: Payzario Inc. | Effective Date: April 2025 | Version: 1.0
1. Purpose
This Information Security Policy establishes the framework for protecting Payzario's information systems, data assets, and technology infrastructure. It applies to all employees, contractors, vendors, and third-party service providers who access Payzario systems.
2. Scope
This policy applies to all Payzario systems, networks, applications, databases (including those hosted on third-party cloud platforms), and all data processed, stored, or transmitted on behalf of Payzario or its customers.
3. Information Security Principles
- Confidentiality: Information is accessible only to those authorized to access it.
- Integrity: Information is accurate and complete and protected from unauthorized modification.
- Availability: Information and systems are available to authorized users when needed.
4. Data Classification
- Confidential: Customer financial data, Plaid access tokens, credentials, PII.
- Internal: Business operations data, internal communications.
- Public: Marketing materials, publicly available content.
5. Security Controls
- All sensitive data is encrypted at rest and in transit using TLS 1.2+.
- Multi-factor authentication (MFA) is required for all admin-level access.
- API keys and secrets are stored in secure environment variable stores — never in source code.
- Infrastructure is hosted on SOC 2-compliant cloud providers.
- Plaid access tokens are stored encrypted and never exposed on the client side.
6. Incident Response
Any suspected security incident must be reported to the designated security contact (admin@payzario.com) within 24 hours of discovery. Payzario will follow a defined incident response plan including containment, investigation, notification, and remediation.
7. Policy Review
This policy will be reviewed annually or following any significant security incident or change in the regulatory environment.
Owner: Payzario Inc. | Contact: support@payzario.com