Security

Pausier Business security and trust.

A public security overview for organisations reviewing Pausier Business for business, public-sector, partner, care, and enterprise use.

Security boundaries apply across the live pressure-moment flow: trigger, pause, pressure signals, reviewer, verification route and outcome record.

Product B Public Protection adds a public/staff boundary: hosted, invite, campaign and QR users remain public users, while Public Case Inbox, Handoff Queue, analytics, delivery actions and audit review remain protected staff surfaces.

Official routes

Use the business domain and published contacts.

Official business site: https://business.pausier.com

Personal Pausier site: https://www.pausier.com

Security contact: security@pausier.com. Support contact: support@pausier.com.

Privacy / DPA route: use the business contact route until a client-specific legal contact is agreed. DPA templates require legal review before client signature.

Data boundary: review the public data-boundary page for staff/public separation, no-sensitive-data rules, controlled external delivery and review readiness.

Official Pausier Business domain

Official business site: https://business.pausier.com. Personal Pausier site: https://www.pausier.com.

Security contact

Security contact: security@pausier.com. Support contact: support@pausier.com. Privacy and DPA questions should use the business contact route until a client-specific legal contact is agreed.

Decision-support boundary

Pausier Business helps teams pause at the moment of pressure, check signals, involve a trusted reviewer, verify through approved routes, and record the outcome. It does not replace banks, police, regulators, emergency services, legal advice, financial advice, safeguarding authorities, or official verification routes.

No sensitive credentials rule

Pausier must not ask for passwords, OTPs, full card numbers, bank logins, private keys, recovery phrases, or unnecessary sensitive financial details.

Tenant and role boundaries

Business data is scoped by organisation tenant. Owner, manager, worker, operator, and partner-route surfaces are separated by route and role checks.

Business owner / manager / worker access model

Owners manage setup and oversight, managers review team decisions, and workers create checks and records. Customer users do not access Pausier operator controls.

Partner integration security boundary

Partner routes require approved onboarding, exact route configuration, support ownership, data-boundary acceptance, sandbox validation, and production approval.

API / Webhook / SDK security approach

Partner API keys are treated as server-side credentials, webhook signing uses approved endpoint metadata, and SDK/deep integrations use a partner backend or short-lived token model rather than long-lived client app keys.

Data minimisation

Pausier Business records only the context needed for decision support, review, history, support handoff, and approved integration flows.

Audit/history model

Checks, reviews, outcomes, case history, support tickets, partner events, and operator actions are designed to create an accountable record without certainty labels.

Incident reporting

Security and operational incidents should be reported through security@pausier.com or the approved support route for triage and response.

Vulnerability reporting

Responsible disclosure should go to security@pausier.com with reproduction steps, affected route, and safe evidence only.

Data retention/deletion readiness

Retention, deletion, and export workflows are documented as readiness controls and require approved operational/legal review before customer contract use.

Privacy, DPA, and subprocessor readiness

Pausier Business maintains data-map, DPA-readiness, retention/deletion/export, and subprocessor-readiness materials. Templates require legal review before client signature.

What Pausier does not do

Pausier does not guarantee outcomes, prove fraud, prove safety, replace emergency or official routes, request sensitive credentials, or publish unapproved partner/customer claims.

Security assurance without unsupported certification claims

Security review, monitoring, incident response, DPA readiness, subprocessor review, and enterprise assurance work are tracked honestly. Public certification or approval claims require real evidence before publication.

Boundary

Decision-support only.

Pausier does not guarantee outcomes, prove fraud, prove safety, replace official routes, or request sensitive credentials.

Security | Pausier Business