1. Home
  2. Product
  3. Software security

Software security

PayAnalytics' high security standards

We know that your data is extremely sensitive, and guaranteeing data security a top priority. PayAnalytics and beqom maintains compliance with the following frameworks for its development and operating procedures:

  • ISO/IEC 27001:2022 with the additional implementation guidance and extended control sets from ISO/IEC 27017:2015 and ISO/IEC 27018:2019.
  • ISAE3402/SOC 1 Type II
  • SOC 2 Type II
  • GDPR

Pentests are performed annually.

A graphic showing a security badge.

Our security practices

Data security is a fundamental concern for the PayAnalytics platform. Designed to provide peace of mind, our software solution is certified to a high-security standard and follows industry best practices data handling and storage.

Data Security Cloud graphic

Cloud security

We follow industry best practices to ensure the confidentiality of your data. For example, we employ encryption in transit (HTTPS/TLSv1.3) and encryption at rest (disk-level encryption). All System Administrator actions are audited to further guarantee data confidentiality. If you stop using PayAnalytics, all your data will be permanently removed from our systems after the backup retention period expires (30 days).

Data storage

Each PayAnalytics customer is assigned a designated system instance with all data stored in a dedicated database namespace, separate from other customers. Depending on customer location, data is stored and processed in data centers in either Ireland (EU), Northern Virginia (US) or Montreal (Canada), each complying with local laws and regulations.

Authentication

PayAnalytics customer instances can be configured with either:

  • Authentication with a username and password, with multiple configurable password policies. In addition, PayAnalytics supports two-factor authentication (2FA) for increased security. User passwords are stored only in hashed/salted form.
  • Authentication with single sign-on (SAML or OIDC) allows you to manage your users’ access to PayAnalytics through an external authentication solution. We support Azure AD, Ping Identity, Okta, and other solutions.

Any further questions about data security?

For more details about security, contact our security team, they will be happy to answer any questions you might have.

Want to know more about PayAnalytics?