Security and trust

Trust is operational—
not decorative.

Security is reflected in how systems are designed, access is controlled, changes are reviewed, incidents are handled, data is protected and responsibilities are defined. It is part of how Pintop builds, implements and supports software.

Security across the system

Identity, access and approval controls

Secure software delivery and controlled change

Data, infrastructure, backup and recovery

Support, escalation and incident handling

Security across the work that
matters.

Our approach covers the product, software delivery, infrastructure, data, people and operational processes surrounding each implementation.

01

Identity and access

Role design, authentication, privileged access, approval controls, credential handling and account administration are aligned with the product and deployment model.

02

Secure software delivery

Product changes move through review, testing, release control, environment separation and traceable delivery processes.

03

Data protection

Data access, collection, retention, deletion, transfers, exports and backups are considered throughout the product and implementation lifecycle.

04

Infrastructure and operations

Hosting responsibilities, network controls, monitoring, logging, patching, backup, recovery and operational escalation are defined for the deployment.

05

Product controls

Permissions, approvals, audit trails, session controls and configurable workflows support clearer accountability.

06

People and process

Staff access, confidentiality, onboarding, offboarding, security awareness and escalation form part of the operating process around the technology.

Security is a
shared operating model.

A dependable outcome depends on the product, infrastructure, configuration, users, integrations and support process working together.

The full operating environment

Security is strongest when technical controls, operational processes and client responsibilities are treated as one connected system.

Product

Permissions, approvals, audit trails, sessions and security-relevant product behaviour.

Infrastructure

Networks, environments, monitoring, patching, backups and recovery.

Configuration

Roles, approval rules, workflows and deployment-specific settings.

Users

Account administration, device security, credentials and responsible use.

Integrations

Identity providers, payment systems, APIs and connected third-party services.

Support and response

Incident contacts, escalation, investigation, remediation and communication.

Responsibilities should be
explicit.

Each implementation defines the responsibilities held by Pintop, the client, infrastructure providers and connected third parties.

User and role administration

Device and endpoint security

Hosting and infrastructure ownership

Identity and network providers

Configuration and approval rules

Data quality and lawful processing

Third-party integrations

Incident contacts and escalation

Backup and recovery testing

Custom code and change ownership

Clear expectations around
service reliability.

Availability, support, maintenance, backup and recovery commitments are defined according to the product, deployment model and service agreement applying to the engagement.

Availability

Service availability is considered in relation to the product, hosting arrangement and support scope.

Support priorities

Support requests are assessed according to operational impact, severity and agreed service coverage.

Maintenance and change

Planned and emergency changes follow the communication and release process applying to the service.

Backup and recovery

Backup, retention and recovery responsibilities depend on who owns and operates the hosting environment.

Security reporting

Found something that may affect
security?

Clients, users and security researchers can submit a suspected issue through the Pintop ticket route. Include the affected product, steps to reproduce and enough information for the team to investigate safely.

Submit a security report

Use the ticket form to describe the affected service, observed behaviour, business impact and reproduction steps.

 

Security information

Need material for your
review?

Tell us which Pintop product or service you are evaluating and what your technical, legal, procurement, risk or compliance team needs. Sensitive documentation can be shared through an appropriate controlled process.

Security questionnaire

Architecture and data-flow information

Service and support information

Backup and continuity information

Relevant security documentation