TRUST & RESPONSIBILITY

Keep payment operations controlled and auditable.

Protect the technical layer with explicit access, preserved evidence and clear responsibility boundaries across merchant, PayStar and PSP.

Security is not a badge detached from the payment flow. Teams need to understand where sensitive data travels, who can act, what is recorded and which organisation owns each decision.

[01] security properties the operating model must preserve

Security properties the operating model must preserve

01

Clear scope and data boundaries

Minimise unnecessary exposure, keep payment credentials out of public channels and document where provider-specific data enters the lifecycle.

02

Role-based operating access

Give payment, support, finance and technical roles the access required for their job while keeping privileged actions attributable.

03

Evidence for investigation and audit

Preserve normalized events, original PSP responses, callbacks and authorized corrections as one traceable operating history.

04

Monitoring and response ownership

Detect technical degradation, identify the responsible system and coordinate the next action without confusing platform availability with PSP approval.

05

Contract-backed service availability

PayStar commits to a 99.5% service availability SLA. Financial responsibility if this service level is not met is defined directly in the contract.

[02] responsibility does not disappear behind the platform

Responsibility does not disappear behind the platform

The merchant owns provider selection, commercial terms and routing policy. PayStar owns the technical orchestration layer. Each PSP remains responsible for processing and settlement under its direct contract.

[03] current evidence

Ask for current evidence

Certification status, service levels and other assurances should identify their scope, current source, date and accountable owner. General website language should not be treated as a substitute for contractual evidence.