
Security
Institutional-Grade Data Protection
Payables data is sensitive, so we prefer stating the controls we actually operate rather than slogans. Here is what is in place today.

Encryption in transit and at rest
All traffic is served over TLS 1.3. Stored data, files and backups are encrypted at rest with AES-256.
Enforced tenant separation
Access rules are applied in the database itself, so one buyer or supplier can never read another's invoices, banking details or users.
Managed credentials
Passwords are system-generated with high entropy, stored only as modern cryptographic hashes, and must be replaced on first sign-in.
Audit logging
Every settlement, rate change, enrolment and administrative action is recorded with the user and timestamp behind it.
Safe file handling
Inbound invoice files are validated and screened for duplicates; exported spreadsheets are sanitised against formula injection.
Certified infrastructure
The platform runs on cloud infrastructure holding SOC 2 Type II and ISO 27001 certifications, with automated backups.
Certification Status
Our hosting and infrastructure providers are independently certified to SOC 2 Type II and ISO 27001. PegaTrade Finance's own corporate certification is in progress, and we are glad to complete vendor security questionnaires and share our current control documentation during procurement.
Request Our Security Pack

