AI Payment Guard is a financial control plane. The bar is higher than for a generic SaaS, and we treat it that way. Below: what we do today, what we're working on, and how to report a problem.
EU-hosted by default. Standard Contractual Clauses for any non-EU sub-processor. Customer-facing DPA available.
Audit observation period started Q1 2026. Target attestation: Q4 2026.
Targeted for 2027 alongside our Enterprise plan rollout.
We never process or store cardholder data. Card payments live in your underlying rail (Stripe, etc.).
Healthcare-specific PHI is not currently supported. Contact us for industry-specific deployments.
Customer data resides in the EU by default. Other regions available on Enterprise plans.
We welcome reports from security researchers. If you believe you've found a vulnerability, please email security@payment-guard.example with reproduction details. We aim to acknowledge within 24 hours and provide a fix timeline within 5 business days.
We acknowledge contributors publicly (with their consent) on our security disclosures page once an issue is resolved.
Need our SOC 2 progress letter, the latest pentest summary, or a signed DPA?
Request our security packet โ