VisaPathways

Enterprise

Security & trust

How VisaPathways protects enterprise API access, isolates customer activity, and preserves auditable compliance evaluation records.

Current security controls

Credential security

Production API credentials are generated once. VisaPathways stores a SHA-256 hash rather than the raw credential, and credentials can be revoked or expired.

Tenant isolation

Enterprise API requests are authenticated to a tenant. Historical evaluation retrieval is tenant-scoped and does not expose another tenant's evaluation by identifier.

Auditability

Compliance evaluations persist the selected rule version, compiled hash, verdict, reason codes, evidence references and evaluation trace for later review.

Controlled rule lifecycle

Published compliance rules move through an explicit authoring lifecycle and retain effective dates, provenance and immutable version identity.

Usage monitoring

Authenticated enterprise API activity is recorded for operational monitoring, including endpoint, status, outcome, errors and rate-limit events. Raw API keys and request bodies are not written to the usage ledger.

Least-privilege data access

Database roles used by the compliance service are granted the permissions required for the API workflow rather than broad public access.

Certification status

VisaPathways does not currently claim SOC 2, ISO 27001 or another third-party security certification. Security questionnaires and architecture information can be discussed during enterprise evaluation. This page describes current product controls and is not a certification report.

Security contact

For a security question, suspected vulnerability, or enterprise due-diligence request, contact VisaPathways and mark the request as security-related.

Contact VisaPathways