SevenRail
HomePlatformEcosystemSolutionsDevelopersCompanyContact
  • PT Português
  • EN English
  • ES Español
Talk to our team
  • PT Português
  • EN English
  • ES Español
Trust Center / Security Policy

Security Policy

Overview of SevenRail security program and practices.

1.0 - Updated 15 days ago Active
On this page
  • 01 Introduction
  • 02 Our Security Principles
  • 03 Security Governance
  • 04 Infrastructure Security
  • 05 Identity and Access Management
  • 06 Encryption
  • 07 Network Security
  • 08 Secure Software Development
  • 09 Vulnerability Management
  • 10 Logging and Monitoring
  • 11 Incident Response
  • 12 Business Continuity and Disaster Recovery
  • 13 Customer Responsibilities
  • 14 Third-Party Providers
  • 15 Compliance
  • 16 Policy Updates
  • 17 Contact

On this page

  • 01 Introduction
  • 02 Our Security Principles
  • 03 Security Governance
  • 04 Infrastructure Security
  • 05 Identity and Access Management
  • 06 Encryption
  • 07 Network Security
  • 08 Secure Software Development
  • 09 Vulnerability Management
  • 10 Logging and Monitoring
  • 11 Incident Response
  • 12 Business Continuity and Disaster Recovery
  • 13 Customer Responsibilities
  • 14 Third-Party Providers
  • 15 Compliance
  • 16 Policy Updates
  • 17 Contact

Need help?

If you have any questions about this document, our team is here to help.

Contact us

Contact Legal

legal@keldan.com.br

01

Introduction

Security is a fundamental principle of the SevenRail platform.

We are committed to designing, building, and operating our Services using security best practices that help protect the confidentiality, integrity, and availability of customer information.

This Security Policy provides an overview of our security program. It is intended for informational purposes only and does not create contractual obligations unless expressly incorporated into a written agreement.


02

Our Security Principles

Our security program is built upon the following principles:

  • Security by Design
  • Privacy by Design
  • Least Privilege
  • Defense in Depth
  • Continuous Monitoring
  • Secure Development Lifecycle
  • Risk-Based Decision Making
  • Continuous Improvement

These principles guide the design and operation of all SevenRail Services.


03

Security Governance

Security is integrated into the development, operation, and maintenance of our Services.

Our governance program includes activities such as:

  • security risk assessments;
  • vulnerability management;
  • infrastructure hardening;
  • secure deployment processes;
  • incident response planning;
  • access reviews;
  • continuous monitoring;
  • periodic policy reviews.

Security responsibilities are shared across engineering, operations, and leadership teams.


04

Infrastructure Security

SevenRail deploys its Services using modern cloud infrastructure designed to provide resilience, scalability, and operational security.

Security measures may include:

  • network segmentation;
  • firewall protection;
  • private networking where appropriate;
  • infrastructure redundancy;
  • automated provisioning;
  • immutable infrastructure practices;
  • secure configuration management;
  • infrastructure monitoring.

Infrastructure architectures evolve continuously as part of our security improvement program.

05

Identity and Access Management

Access to systems is granted according to the principle of least privilege.

Security measures may include:

  • role-based access control (RBAC);
  • multi-factor authentication (MFA);
  • privileged access restrictions;
  • credential rotation;
  • centralized identity management;
  • periodic access reviews;
  • session management.

Administrative access is limited to authorized personnel with legitimate business needs.


06

Encryption

SevenRail uses industry-standard cryptographic technologies to protect information.

Where applicable:

  • data is encrypted in transit using TLS;
  • data may be encrypted at rest;
  • passwords are stored using secure one-way hashing algorithms;
  • secrets are managed through secure secret management systems;
  • encryption standards are periodically reviewed.

07

Network Security

Our network security strategy may include:

  • firewall protections;
  • DDoS mitigation;
  • traffic filtering;
  • secure ingress controls;
  • private network segmentation;
  • rate limiting;
  • API protection mechanisms;
  • continuous traffic monitoring.

Network controls are continuously evaluated and improved.


08

Secure Software Development

Security is incorporated throughout the software development lifecycle.

Development practices may include:

  • secure coding standards;
  • peer code reviews;
  • dependency management;
  • automated testing;
  • vulnerability scanning;
  • secret detection;
  • continuous integration;
  • controlled production deployments.

Security considerations are integrated throughout the engineering process.


09

Vulnerability Management

SevenRail continuously evaluates security risks affecting the Services.

Our vulnerability management process may include:

  • automated vulnerability scanning;
  • dependency monitoring;
  • infrastructure assessments;
  • security updates;
  • patch management;
  • risk prioritization;
  • remediation tracking.

Critical vulnerabilities receive priority attention according to their assessed risk.

10

Logging and Monitoring

Security events may be logged and monitored to:

  • detect unauthorized activity;
  • investigate incidents;
  • improve operational visibility;
  • support forensic analysis;
  • protect platform integrity.

Monitoring is conducted in accordance with applicable laws and our Privacy Policy.


11

Incident Response

SevenRail maintains processes designed to identify, assess, contain, investigate, and remediate security incidents.

Our incident response process generally includes:

  • detection;
  • assessment;
  • containment;
  • eradication;
  • recovery;
  • post-incident review.

Where legally required, affected parties and competent authorities may be notified in accordance with applicable law.


12

Business Continuity and Disaster Recovery

SevenRail maintains operational procedures intended to improve service resilience and recovery capabilities.

These procedures may include:

  • backup strategies;
  • infrastructure redundancy;
  • disaster recovery planning;
  • operational monitoring;
  • recovery testing;
  • change management.

Recovery objectives vary depending on the applicable Service.


13

Customer Responsibilities

Security is a shared responsibility.

Customers are expected to:

  • maintain strong authentication practices;
  • protect account credentials;
  • enable MFA where available;
  • configure integrations securely;
  • promptly report suspected security incidents;
  • maintain appropriate internal security controls.

Customers remain responsible for the security of their own environments and systems.


14

Third-Party Providers

SevenRail works with carefully selected infrastructure and technology providers.

Third-party providers are expected to maintain appropriate security standards consistent with the services they provide.

Information regarding infrastructure providers may be available through our Subprocessors or Legal Center documentation where applicable.


15

Compliance

SevenRail continuously seeks to improve its security program and align with recognized industry best practices.

As our platform evolves, we may pursue additional security certifications, audits, or compliance frameworks appropriate to our Services and business operations.


16

Policy Updates

This Security Policy may be updated periodically to reflect improvements to our security program, legal requirements, or operational practices.

The most current version will be published through the SevenRail Legal Center.


17

Contact

Security Team

security@SevenRail.com.br

Legal

legal@SevenRail.com.br

Privacy

privacy@SevenRail.com.br

Website

https://www.SevenRail.com.br

Your trust is our priority.

We are committed to transparency, security and compliance in everything we do.

View our Privacy Policy
SevenRail

Payment orchestration infrastructure connecting businesses with PSPs, banks, payment rails and financial networks at global scale.

Platform

  • Orchestration
  • Routing
  • Unified API

Resources

  • Developers
  • Documentation
  • Status
  • Trust

Company

  • About
  • Contact

SevenRail by Keldan.

© 2026 SevenRail. All rights reserved.

TermsPrivacyCookiesSecurity

Payment Infrastructure · Global