Security
Last updated: July 2026Technical and Organizational Measures
POWR is committed to protecting the personal data of merchants and their customers. This page describes the technical and organizational measures POWR maintains to secure personal data processed through its services.
These measures are incorporated by reference into POWR's Data Processing Agreement and constitute Annex II to the Standard Contractual Clauses incorporated therein.
System Access Controls
-
Multi-factor authentication (MFA) required for all employee access to POWR business systems, with passkeys (WebAuthn) required for privileged and production system access.
-
Role-based access control (RBAC) limiting data access by role
-
Regular access reviews (annually)
-
Automated deprovisioning upon employee termination
-
Session timeout policies
-
IP whitelisting for sensitive systems
Data Access Controls
-
Encryption at rest using AES-256
-
Encryption in transit using TLS 1.2+
-
Database-level access controls
-
Audit logging of all data access
-
Data minimization principles applied
-
POWR operates a four-tier data classification framework. Customer Personal Data is classified as Restricted — the highest tier — subject to the most stringent access, storage, and handling controls.
Transmission Controls
-
Secure file transfer protocols (SFTP, HTTPS)
-
Email encryption for sensitive communications
-
Data loss prevention controls monitoring and restricting unauthorized external sharing of data and credentials
Input Controls
-
Data validation and sanitization
-
Input filtering to prevent injection attacks
-
Form validation on client and server side
-
Rate limiting to prevent abuse
Availability Controls
-
Daily automated backups
-
Geographically redundant backup storage
-
Disaster recovery plan with RTO/RPO targets
-
DDoS mitigation and load balancing
Separation Controls
-
Logical separation of customer data in multi-tenant environment
-
Customer data isolation through database partitioning
-
Separate development, staging, and production environments
-
Network segmentation
Organizational Measures
-
Information security policy reviewed annually
-
Security awareness training for all employees (annually)
-
Confidentiality agreements signed by all personnel
-
Incident response plan and procedures
-
Designated security team
-
Google Cloud Platform (GCP) infrastructure is covered by GCP's SOC 2 / ISO 27001 program; POWR conducts periodic internal application-level security reviews and vulnerability assessments.
-
Vulnerability scanning (weekly)
Logging and Monitoring
-
Centralized logging of security events
-
Real-time alerting for suspicious activities
-
Log retention for 1 year
-
SIEM (Security Information and Event Management) tools deployed
Pseudonymization and Encryption
-
Customer data encrypted at rest and in transit
-
Pseudonymization is available for certain data types upon request
-
Data at rest is encrypted using AES-256 via Google Cloud's default encryption-at-rest mechanism with Google-managed encryption keys and automatic key rotation managed by GCP.