1. Security architecture
Pementek is designed around a layered security model that protects payment communication, transaction integrity, merchant integrations and platform access throughout the transaction lifecycle.
Our architecture combines authenticated APIs, encrypted communication, controlled access, server-side transaction verification, signed event delivery, operational monitoring and resilient transaction processing.
These controls are designed to work together so that security is not dependent on a single component, device, provider or customer-side action.
2. Encryption and secure communication
Pementek uses encrypted communication for protected web and API traffic to help safeguard information moving between merchant systems, Pementek services and supported payment infrastructure.
Secure transport helps protect transaction information against unauthorized interception or modification while data is moving between systems.
3. Secure API access
Pementek APIs are designed for authenticated server-to-server communication between Pementek and authorized merchant systems.
API credentials should be stored only in appropriately secured backend environments and should never be exposed in browser code, public repositories or untrusted client applications.
Access controls help ensure that protected API operations are available only to authorized systems and users.
4. Transaction integrity
Pementek treats the server-side transaction engine as the authoritative source of payment and payout status.
Browser redirects, customer messages and other client-side indicators are not treated as independent proof that a financial transaction has completed.
Transactions are processed through controlled states and are finalized only when the platform has the required transaction evidence or authoritative result.
5. Verification-first payment security
Local payment methods can behave differently across markets, providers and network conditions. Pementek is designed to verify transaction evidence before declaring a transaction successful.
This verification-first approach reduces reliance on untrusted customer-side signals and helps maintain consistent transaction integrity across supported payment methods.
6. Signed webhooks
Pementek delivers supported transaction updates to merchant systems through signed server-to-server webhooks.
Merchants should verify webhook signatures before accepting an event as authentic and before using the event to update internal order or payment state.
This provides an additional layer of protection against unauthorized or fabricated transaction notifications.
7. Idempotent transaction requests
Network interruptions and temporary application failures can cause merchants to retry requests. Pementek supports idempotent transaction operations to help prevent accidental duplicate processing.
Merchants should use stable idempotency identifiers in accordance with Pementek API documentation when retrying supported transaction operations.
8. Payments and payouts
Pementek applies the same security-first principles to payment collection and payout processing.
Payment flows are designed to require verified transaction evidence before final success, while payout flows require appropriate authorization and verified outgoing transaction evidence before they are treated as completed.
This helps protect merchants and customers against false confirmations, duplicate processing and inconsistent transaction states.
9. Asynchronous transaction safety
Local payment infrastructure is not always instantaneous. Network delays, provider response times and verification conditions can affect when a final transaction result becomes available.
Pementek uses asynchronous transaction states so that delayed verification can be handled safely without incorrectly assuming that an unresolved transaction has failed.
10. High availability
Pementek infrastructure is engineered for 99.99% uptime and dependable transaction processing across payment and payout operations.
High availability is supported by resilient platform design, controlled transaction state management, operational monitoring and fault-aware processing patterns.
The objective is to keep merchant integrations stable even when individual payment providers, networks or external systems experience temporary disruption.
11. Reliability by design
Reliability is treated as part of transaction security because inconsistent system behaviour can create financial risk.
Pementek uses controlled transaction states, idempotent operations, authoritative server-side results and asynchronous processing patterns to maintain predictable behaviour under real-world payment conditions.
12. Access control
Access to protected Pementek services is designed to be restricted to authorized users, merchant systems and operational services.
Access should follow the principle of least privilege, meaning users and systems should receive only the access required for their legitimate responsibilities.
13. Credential protection
API keys, passwords, private keys and other authentication credentials must be treated as sensitive information.
Merchants should not transmit credentials through Telegram, ordinary messages, browser code or public source repositories.
If credentials are believed to have been exposed, merchants should take appropriate action promptly and contact Pementek where assistance is required.
14. Data protection
Pementek applies technical and organizational safeguards designed to protect information against unauthorized access, alteration, misuse, loss or disclosure.
Access to protected information is intended to be limited to systems, personnel and service providers that require it for legitimate operational, security, support or compliance purposes.
Additional information about personal information handling is available in thePrivacy Policy.
15. Monitoring and detection
Pementek may maintain operational logs, transaction records, infrastructure telemetry and security events needed to operate and protect the platform.
Monitoring can help identify abnormal transaction behaviour, unauthorized access attempts, platform errors and other conditions that may affect security or reliability.
16. Fraud and financial crime controls
Security controls operate alongside compliance and transaction monitoring measures designed to reduce fraud, money laundering, sanctions evasion and other prohibited financial activity.
More information about Pementek's financial crime approach is available in theAML Policy.
17. Infrastructure resilience
Pementek is designed to operate across payment environments where temporary network, provider or verification interruptions can occur.
Transaction processing is structured so that a temporary external issue does not automatically require an unsafe transaction decision.
This architecture supports secure recovery, reconciliation and continuation of supported payment workflows.
18. Merchant security responsibilities
Security is a shared responsibility. Merchants using Pementek should maintain strong security controls in their own applications and infrastructure.
Recommended merchant practices include:
- Protect API credentials and account access
- Use HTTPS for protected server communication
- Verify signed webhook events
- Use idempotency for supported API operations
- Restrict access to sensitive systems
- Keep software and dependencies appropriately maintained
- Monitor merchant systems for unauthorized activity
- Never rely on browser redirects as final transaction proof
19. Responsible security disclosure
If you believe you have identified a vulnerability or security issue affecting Pementek, please report it privately so that our team can investigate the matter.
Security contact
pementek@protonmail.comPlease provide sufficient technical information to understand the issue, and do not publicly disclose a suspected vulnerability before Pementek has had a reasonable opportunity to investigate and address it.
20. Continuous improvement
Security architecture must evolve as technologies, threats, markets and payment infrastructure change.
Pementek may continuously improve its security, encryption, reliability, monitoring and operational controls as the platform develops.
21. Contact
For security-related questions or responsible disclosure, contactpementek@protonmail.com.
For general business or integration inquiries, visit the Contact page.
