Security is reflected in how systems are designed, access is controlled, changes are reviewed, incidents are handled, data is protected and responsibilities are defined. It is part of how Pintop builds, implements and supports software.
Security across the system
Identity, access and approval controls
Secure software delivery and controlled change
Data, infrastructure, backup and recovery
Support, escalation and incident handling
Our approach covers the product, software delivery, infrastructure, data, people and operational processes surrounding each implementation.
01
Role design, authentication, privileged access, approval controls, credential handling and account administration are aligned with the product and deployment model.
02
Product changes move through review, testing, release control, environment separation and traceable delivery processes.
03
Data access, collection, retention, deletion, transfers, exports and backups are considered throughout the product and implementation lifecycle.
04
Hosting responsibilities, network controls, monitoring, logging, patching, backup, recovery and operational escalation are defined for the deployment.
05
Permissions, approvals, audit trails, session controls and configurable workflows support clearer accountability.
06
Staff access, confidentiality, onboarding, offboarding, security awareness and escalation form part of the operating process around the technology.
A dependable outcome depends on the product, infrastructure, configuration, users, integrations and support process working together.
Security is strongest when technical controls, operational processes and client responsibilities are treated as one connected system.
Permissions, approvals, audit trails, sessions and security-relevant product behaviour.
Networks, environments, monitoring, patching, backups and recovery.
Roles, approval rules, workflows and deployment-specific settings.
Account administration, device security, credentials and responsible use.
Identity providers, payment systems, APIs and connected third-party services.
Incident contacts, escalation, investigation, remediation and communication.
Each implementation defines the responsibilities held by Pintop, the client, infrastructure providers and connected third parties.
User and role administration
Device and endpoint security
Hosting and infrastructure ownership
Identity and network providers
Configuration and approval rules
Data quality and lawful processing
Third-party integrations
Incident contacts and escalation
Backup and recovery testing
Custom code and change ownership
Availability, support, maintenance, backup and recovery commitments are defined according to the product, deployment model and service agreement applying to the engagement.
Service availability is considered in relation to the product, hosting arrangement and support scope.
Support requests are assessed according to operational impact, severity and agreed service coverage.
Planned and emergency changes follow the communication and release process applying to the service.
Backup, retention and recovery responsibilities depend on who owns and operates the hosting environment.
Clients, users and security researchers can submit a suspected issue through the Pintop ticket route. Include the affected product, steps to reproduce and enough information for the team to investigate safely.
Use the ticket form to describe the affected service, observed behaviour, business impact and reproduction steps.
Tell us which Pintop product or service you are evaluating and what your technical, legal, procurement, risk or compliance team needs. Sensitive documentation can be shared through an appropriate controlled process.
Security questionnaire
Architecture and data-flow information
Service and support information
Backup and continuity information
Relevant security documentation