Program governance
Pacorda, Inc. maintains a risk-based security program designed for enterprise payment technology and the sensitivity of the information processed. Technology, engineering, and security services operate under appropriate organizational and service-provider controls.
Program responsibilities, risk acceptance, policies, control ownership, incidents, exceptions, and material remediation are assigned to accountable personnel and reviewed on a recurring basis. Public descriptions do not expose configurations that would weaken protection.
Shared responsibility
Pacorda protects the platform components within its control. Customers remain responsible for their devices, identity providers, email systems, networks, ERP environments, authorized-user lists, approval policies, uploaded data, and lawful payment instructions. Financial partners protect and operate their own systems under separate obligations.
Identity and access
Controls are designed around unique identities, multi-factor authentication, least privilege, role and entity restrictions, session management, access review, separation of duties, and step-up authentication for consequential actions.
No single user should be able to request, independently verify, approve, and activate a protected bank-destination change. Credentials, authenticator codes, and full bank details are not accepted through ordinary email.
Payment integrity
Protected payment details—including amount, currency, beneficiary, funding source, destination, and invoice allocation—are bound to approval. A material change invalidates prior approval and may trigger fresh authentication, compliance screening, and authorization.
Duplicate detection, provider acknowledgments, settlement evidence, reconciliation, ERP confirmation, returns, and exceptions are maintained as distinct events to avoid converting an operational failure into a false bank outcome.
Data protection
Security measures may include encryption in transit and at rest where appropriate, secrets management, environment separation, masking or tokenization, data minimization, protected backups, controlled exports, retention rules, and secure deletion.
Pacorda seeks to avoid exposing full financial credentials in user interfaces, logs, communications, analytics, or support workflows. Access is limited by role and legitimate business need.
Secure engineering
Development practices are designed to include change control, peer review, dependency management, testing, environment separation, vulnerability remediation, and controlled release. Risk-sensitive functionality receives additional review appropriate to consequence.
Supporting tools may assist development and detection, but consequential security, compliance, and payment actions remain governed by approved rules, authorization, explainable evidence, and human escalation where required.
Monitoring and detection
Security telemetry may be used to identify anomalous access, abuse, credential attacks, unauthorized changes, suspicious payment activity, configuration drift, service degradation, and provider failures. Alerts are triaged according to severity, confidence, business impact, and legal obligations.
Incident response
Pacorda maintains procedures designed to identify, contain, investigate, remediate, recover from, document, and learn from incidents. Response may involve customers, financial providers, infrastructure vendors, advisers, insurers, authorities, and affected individuals.
Notifications are provided as required by applicable law and executed contracts. Facts may be supplied in phases while investigation continues.
Resilience and recovery
Business-continuity and recovery measures are designed around service criticality, provider dependencies, backups, restoration, fail-safe behavior, communications, and reconciliation after disruption. Processing, settlement, and ERP status remain separately recoverable.
Third-party risk
Providers are evaluated proportionately to service criticality, access, data sensitivity, regulatory role, geographic exposure, resilience, and substitutability. Contracts should address confidentiality, security, incident notice, use restrictions, deletion, and oversight appropriate to the relationship.
Assurance and limitations
Security documentation, questionnaires, independent reports, penetration-test summaries, or other assurance materials may be made available under confidentiality when applicable and available. This page does not claim a certification, audit opinion, compliance status, or control implementation that has not been formally completed and authorized for publication.
No system is completely secure. Pacorda continuously evaluates risk and may update controls as technology, threats, providers, and legal requirements change.
Report a concern
Report suspected vulnerabilities through the Responsible Disclosure process or to [email protected]. Customers should use authenticated support for account or payment concerns. Do not send credentials, authenticator codes, full bank details, or payment instructions by email.