Designed for customers whose security teams will audit us.
Txnworks processes financial transaction data on behalf of banks, PSPs, and e-commerce risk ops teams. We design controls to the standard those customers' security questionnaires ask for — and we state clearly what we do and do not claim.
Data isolation, encryption, access controls.
Data Isolation
Customer transaction data is stored in logically isolated namespaces. Cross-tenant data access is architecturally prevented — not just access-controlled. Each API key maps to a single tenant namespace.
Encryption In Transit + At Rest
All API traffic requires TLS 1.3 — TLS 1.2 and below are rejected. Data at rest is encrypted using AES-256. Optional field-level encryption for PII fields (name, email, address) available on Scale plans.
Access Controls
API keys are scoped (score-only vs full-access). IP allowlisting supported for all plans. Key rotation via dashboard or API with zero-downtime overlap window. Audit log of all key operations exported on request.
What we store, for how long.
The specifics matter to your legal and compliance teams. Here they are without the vague language.
Security controls by the fact.
Found a vulnerability? Tell us.
We ask that security researchers give us reasonable time to investigate and fix issues before public disclosure. We will not pursue legal action against researchers acting in good faith.