Read-Only by Design

Canyon Insights connects to supported payment gateways using secure, read-only API credentials. The platform is built exclusively for visibility, reporting, and analytics—with no ability to take action on live transactions.

What this means for you:

  • Canyon Insights can view reporting and transaction detail data from your connected gateways
  • The platform cannot process, initiate, or modify transactions
  • Refunds, voids, and operational changes remain fully controlled within your gateway
  • API access can be revoked at any time

PCI Scope & Cardholder Data 

Canyon Insights is a reporting and analytics platform and is not a payment processor. The platform is designed to operate outside of the cardholder data environment.

What this means

  • Canyon Insights does not store full card numbers
  • Payment transactions are processed entirely within your payment gateway
  • Canyon Insights does not initiate, route, or authorize payment transactions
  • Card data received from gateway APIs is limited to masked or truncated values (e.g., last four digits)

PCI compliance responsibility for payment processing remains with your payment gateway and acquiring bank.

Platform Security

Canyon Insights follows industry-standard security practices to protect customer data.

Our approach includes

  • Encrypted data in transit using industry-standard encryption protocols
  • Encrypted data at rest within our platform
  • Role-based access controls and least-privilege permissions
  • Infrastructure hosted on Amazon Web Services (AWS), including serverless compute, S3 storage, and CloudFront content delivery, with Cloudflare routing for additional network protection
  • Strong password requirements enforced for all accounts, including minimum length, mixed case, numbers, and special characters
  • Automatic session timeouts to protect against unauthorized access on unattended devices

Data Handling & Retention

Canyon Insights follows a data-minimization approach, collecting and retaining only the data necessary to deliver reporting and analytics to your team.

Our practices include

  • Customer data is never sold or shared for marketing purposes
  • Access to data is limited to authorized personnel on a need-to-know basis
  • You can disconnect your payment gateway at any time to stop data syncing; contact support to request deletion of previously synced data