Security + compliance
No card data touches us. Charges run on your PCI-DSS Level 1 processor; multiflow orchestrates the ledger on top. SOC-2-aligned infra, US-only residency, TLS 1.3 end-to-end, per-entity audit log on every change.
Compliance posture
SAQ D-SP service provider scope. Tokens only — no PAN. Attestation + memo under NDA.
Type I complete Q1 2026. Type II audit underway, target Q3 2026. Security · Availability · Confidentiality.
DPA on request. US-only residency default. 30-day DSR + deletion workflow.
Payment data is financial-exempt (45 CFR 164.501). No PHI stored. BAA on edge cases.
Target Q1 2027. Already mapped to ISO 27002:2022 Annex A — pre-audit document available.
Visa Core · Mastercard Chargeback · Amex OnePoint. Representment tracks current rulebooks.
Core controls
PCI-DSS scope stays on your processor. Tokens flow through multiflow; PANs never do.
Every parent ↔ sub-brand call encrypted in transit. HSTS preload list entry enforces HTTPS at browser level.
Every row in the ledger encrypted. Per-row key envelope via AWS KMS. 90-day key rotation.
Every role scoped to specific sub-brands. Permissions reviewed quarterly.
Per-entity audit log on every settings change. SIEM-forwarded. Immutable archive.
Every parent → sub-brand handoff signed. Idempotency keys + at-least-once retry.
Every operator login. WebAuthn / FIDO2 hardware key support for privileged roles.
Per-sub-brand IP allowlists available for admin actions.
Every API endpoint. ML-based anomaly scoring on unusual traffic patterns.
Production deploys require 2-engineer approval. DBA access gated behind break-glass escalation.
How data flows
Direct from customer to the processor over TLS 1.3. Never routed through us.
Stripe · Square · Authorize.net returns a token. PAN stays inside their PCI boundary.
We set the per-brand descriptor, write the ledger row. No PAN, ever.
CRM · CX · analytics get HMAC-signed event payloads — never card data.
Sub-processors
| Vendor | Purpose | Data scope | Region |
|---|---|---|---|
| AWS | Compute, storage, KMS | Orchestration data (encrypted) | US |
| Cloudflare | CDN, WAF, DDoS | Request metadata, no payloads | Global edge |
| Datadog | Application monitoring | Metrics + logs (PII redacted) | US |
| Stripe / Square / Authorize.net | Payment processing (yours) | Full charge data | Per processor |
| SendGrid | Transactional email | Operator emails only, no customer data | US |
| Sentry | Error tracking | Errors + stack traces (PII redacted) | US |
| PagerDuty | Incident alerting | Metadata on incidents only | US |
Compute · storage · KMS
Orchestration data, encrypted at rest.
CDN · WAF · DDoS
Request metadata only, no payloads.
Application monitoring
Metrics + logs (PII redacted).
Payment processing (yours)
Full charge data — PCI boundary lives here.
Transactional email
Operator emails only — no customer data.
Error tracking
Errors + stack traces, PII redacted.
Incident alerting
Metadata on incidents only.
Enterprise customers notified 30 days before any material change. DPA template available on request.
Incident response
Automated alerting (Datadog + PagerDuty). On-call engineer acknowledges within 15 minutes. Severity triaged P1 / P2 / P3 / P4.
P1 containment deployed within 60 minutes. Status page updated. Affected operators notified via email + Slack.
Fix deployed, monitoring confirms resolution. Affected operators receive all-clear notification.
Internal PIR. Root cause, timeline, impact, corrective actions documented. Customer-facing summary for material incidents.
GDPR 72-hour breach rule, CCPA 30-day, card network timeframes. Coordinated with operator legal teams when relevant.
Offensive testing
Bug bounty
Business continuity
Active-active across two AWS regions. Quarterly DR tests. Even in a full multiflow outage your processor keeps taking payments — our failure mode is orchestration lag, not payment failure.
Shared responsibility
multiflow owns
Operator owns
Trust center
Available under NDA. Type II in progress.
Most recent quarter, under NDA.
Service provider attestation.
GDPR + CCPA ready, operator legal review.
Full architecture + controls overview. Available without NDA.
E&O + cyber liability coverage.
Request packet: security@multi-flow.pro · 48-hour turnaround for enterprise.
Enterprise + regulated customers get direct access to our security team for RFP responses, questionnaires, and compliance syncs.
Talk to an operator
Human reply within 2 business hours. No chatbot.