TRUST & RESPONSIBILITY
Keep payment operations controlled and auditable.
Protect the technical layer with explicit access, preserved evidence and clear responsibility boundaries across merchant, PayStar and PSP.
Security is not a badge detached from the payment flow. Teams need to understand where sensitive data travels, who can act, what is recorded and which organisation owns each decision.
[01] security properties the operating model must preserve
Security properties the operating model must preserve
Clear scope and data boundaries
Minimise unnecessary exposure, keep payment credentials out of public channels and document where provider-specific data enters the lifecycle.
Role-based operating access
Give payment, support, finance and technical roles the access required for their job while keeping privileged actions attributable.
Evidence for investigation and audit
Preserve normalized events, original PSP responses, callbacks and authorized corrections as one traceable operating history.
Monitoring and response ownership
Detect technical degradation, identify the responsible system and coordinate the next action without confusing platform availability with PSP approval.
Contract-backed service availability
PayStar commits to a 99.5% service availability SLA. Financial responsibility if this service level is not met is defined directly in the contract.
[02] responsibility does not disappear behind the platform
Responsibility does not disappear behind the platform
The merchant owns provider selection, commercial terms and routing policy. PayStar owns the technical orchestration layer. Each PSP remains responsible for processing and settlement under its direct contract.
[03] current evidence
Ask for current evidence
Certification status, service levels and other assurances should identify their scope, current source, date and accountable owner. General website language should not be treated as a substitute for contractual evidence.