Security & money safety

Unknown is a state.
Never a guess.

PerionPayments is engineered to retain evidence, constrain authority, and refuse unsafe movement when a provider or network cannot give a certain answer.

01

Duplicate-debit protection

Only one active provider attempt is admitted for a payment. Unknown outcomes remain processing while callbacks, queries, provider files, or bank records resolve them.

02

Immutable financial evidence

Balanced double-entry journals, append-only event histories, checksummed exports, and reversal-plus-replacement corrections preserve the original story.

03

Scoped human authority

Merchant and operator sessions are distinct. Material controls use role checks, cell boundaries, fresh assurance where required, and independent maker-checker decisions.

04

Sensitive-data custody

Secrets, callback bodies, contact details, statements, and export artifacts use purpose-bound encryption. Public and merchant projections omit raw provider evidence.

05

Operational detection

Ledger drift, provider silence, settlement exposure, webhook dead letters, and expired worker leases have machine-readable metrics and paging contracts.

06

Software supply chain

The delivery pipeline builds pinned images, scans them, emits SBOM and provenance artifacts, signs them, and renders digest-only staging manifests.

Responsible disclosure

Report a security concern.

Send the minimum reproducible detail. Do not include live credentials, full payer data, or raw production evidence in email.

security@perionpayments.com →

Compliance claims stay evidence-bound.

Architecture and control implementation do not equal certification. PCI scope, regulatory approval, provider certification, penetration evidence, production operations, and named partner approvals remain external gates until verified. PerionPayments does not present them as complete.

Review current rail and market status →