TLS 1.3
Public traffic is designed for modern TLS termination and secure browser transport.
Security
Silvatech Payments is designed around least exposure, tenant isolation, auditability, and honest compliance scope.
Public traffic is designed for modern TLS termination and secure browser transport.
The public app avoids raw card-data storage; merchant PCI obligations depend on the selected flow.
Tenant configuration, tokens, callbacks, and payment records are scoped by tenant boundaries.
Production hosting details are documented per deployment and reviewed with enterprise customers.
Payment lifecycle activity records request IDs, timestamps, external references, and operator actions.
Security contact details are published through security.txt.
Tenant isolation model
Each tenant keeps its configuration, credentials, callbacks, tokens, and payment records scoped to its own operating boundary.
{
"request_id": "req_7f9b",
"tenant": "tenant_demo",
"event": "payment.captured",
"external_reference": "PAY-BZ-1842",
"operator": "system",
"pii": "masked"
}
What we're not certified for yet
PCI scope, external penetration-test cadence, and data-residency commitments are reviewed during onboarding and enterprise contracting. Public claims stay inside verified controls.
View security.txt