Credential security
Production API credentials are generated once. VisaPathways stores a SHA-256 hash rather than the raw credential, and credentials can be revoked or expired.
How VisaPathways protects enterprise API access, isolates customer activity, and preserves auditable compliance evaluation records.
Production API credentials are generated once. VisaPathways stores a SHA-256 hash rather than the raw credential, and credentials can be revoked or expired.
Enterprise API requests are authenticated to a tenant. Historical evaluation retrieval is tenant-scoped and does not expose another tenant's evaluation by identifier.
Compliance evaluations persist the selected rule version, compiled hash, verdict, reason codes, evidence references and evaluation trace for later review.
Published compliance rules move through an explicit authoring lifecycle and retain effective dates, provenance and immutable version identity.
Authenticated enterprise API activity is recorded for operational monitoring, including endpoint, status, outcome, errors and rate-limit events. Raw API keys and request bodies are not written to the usage ledger.
Database roles used by the compliance service are granted the permissions required for the API workflow rather than broad public access.
VisaPathways does not currently claim SOC 2, ISO 27001 or another third-party security certification. Security questionnaires and architecture information can be discussed during enterprise evaluation. This page describes current product controls and is not a certification report.
For a security question, suspected vulnerability, or enterprise due-diligence request, contact VisaPathways and mark the request as security-related.