SECURITY & COMPLIANCE

Security by separation, evidence and controlled acceptance

Trusted PalmPay separates biometric trust, payment value and merchant operations. Standards become scoped engineering controls and test evidence-not unqualified certification claims.

01

Biometric security

Protect capture, transport, template and lifecycle.

PAD reference

Use ISO/IEC 30107-3:2023 for testing and reporting expectations.

Template protection

Use ISO/IEC 24745:2022 principles for protected references and identity binding.

Separation

Keep biometric data outside wallet, ledger and general analytics domains.

02

API & device security

Every device and integration is a trust boundary.

Channel identity

Device certificates, mTLS, signed requests, nonce and replay controls.

API verification

Use OWASP API Security Top 10:2023 as a secure design and test reference.

Fleet assurance

Controlled firmware, configuration, logs, health, disable and incident workflow.

03

Payment integrity & privacy

Business state and personal data require explicit controls.

Ledger

State machine, idempotency, hold/debit/credit/reversal, reconciliation and evidence.

Privacy

Purpose, minimization, consent, retention, access rights and incident response.

Approval

Legal, bank risk, security, privacy and operations approve production scope.

MOBILE-ID

Plan a measurable PalmPay PoC

Align the business case, identity path, terminal mode, bank integration, security controls and acceptance metrics with Mobile-ID.

Contact Mobile-ID