Security & Trust

Built to be trusted with the ledger

Review the security responsibilities, accounting controls and deployment information relevant to your Paprel integration. Confirm the applicable scope before sending production data.

Last reviewed: 9 September 2026

Security controls

Security scope and responsibilities

Confirm the controls and evidence relevant to your deployment before production use.

Data protection

  • The DPA sets obligations for appropriate technical and organisational measures.
  • Confirm encryption coverage, credential access and key management in the deployment security schedule.
  • Use synthetic or properly anonymised data in sandbox; protect production credentials separately.

Ledger integrity

  • Accounting workflows include balanced journals and correction history; validate your mappings and outputs.
  • Review the supported posting and reversal behavior for your integration.
  • Idempotency applies according to the endpoint contract, including key scope and retry requirements.

Access and activity

  • Configure user roles, client scopes and tenant access for your deployment.
  • Verify signed webhook payloads using the documented procedure where supported.
  • Confirm activity coverage, export formats and retention required for your audit needs.

Deployment and recovery

  • Hosting, subprocessors and processing locations must be identified for the applicable service.
  • Hosted and customer-managed deployments have different operational responsibilities.
  • Confirm backup, restore and incident procedures in the security schedule before production processing.
  • Availability targets are distinct from commitments in an agreed SLA.

Data rights and processing

  • Customer Data rights and permitted processing are defined in the Terms and DPA.
  • Supported exports and post-termination access follow the agreed service and exit terms.
  • The DPA and deployment-specific subprocessor and security schedules form the processing package.

The architecture describes product behavior; deployment evidence and the agreed security schedule establish the applicable controls and responsibilities. Explore the architecture.

Evidence and disclosure

Assurance scope and issue reporting

Security diligence should distinguish implemented controls from external certifications and roadmap commitments.

Compliance posture — stated plainly

Paprel does not claim a SOC 2 attestation or ISO 27001 certification here. A cloud provider’s assurance does not certify Paprel or your integration. No certification delivery date is promised. Accounting features do not establish GAAP, IFRS, tax or audit compliance. Request the evidence and deployment scope needed for your review.

Need it for a security review? Request our security overview.

Responsible disclosure

Found a suspected vulnerability? Report it privately and read the linked Vulnerability Disclosure Program before taking further action. This reporting channel does not itself authorise testing. No monetary rewards are offered.

Security contact

security@paprel.com
Read the disclosure program

Operated by NEXARA GLOBAL PTE. LTD. · legal@paprel.com