Duplicate-debit protection
Only one active provider attempt is admitted for a payment. Unknown outcomes remain processing while callbacks, queries, provider files, or bank records resolve them.
PerionPayments is engineered to retain evidence, constrain authority, and refuse unsafe movement when a provider or network cannot give a certain answer.
Only one active provider attempt is admitted for a payment. Unknown outcomes remain processing while callbacks, queries, provider files, or bank records resolve them.
Balanced double-entry journals, append-only event histories, checksummed exports, and reversal-plus-replacement corrections preserve the original story.
Merchant and operator sessions are distinct. Material controls use role checks, cell boundaries, fresh assurance where required, and independent maker-checker decisions.
Secrets, callback bodies, contact details, statements, and export artifacts use purpose-bound encryption. Public and merchant projections omit raw provider evidence.
Ledger drift, provider silence, settlement exposure, webhook dead letters, and expired worker leases have machine-readable metrics and paging contracts.
The delivery pipeline builds pinned images, scans them, emits SBOM and provenance artifacts, signs them, and renders digest-only staging manifests.
Send the minimum reproducible detail. Do not include live credentials, full payer data, or raw production evidence in email.
Architecture and control implementation do not equal certification. PCI scope, regulatory approval, provider certification, penetration evidence, production operations, and named partner approvals remain external gates until verified. PerionPayments does not present them as complete.
Review current rail and market status →