Read-Only by Design
Canyon Insights connects to supported payment gateways using secure, read-only API credentials. The platform is built exclusively for visibility, reporting, and analytics—with no ability to take action on live transactions.
What this means for you:
PCI Scope & Cardholder Data
Canyon Insights is a reporting and analytics platform and is not a payment processor. The platform is designed to operate outside of the cardholder data environment.
What this means
Canyon Insights does not store full card numbers
Payment transactions are processed entirely within your payment gateway
Canyon Insights does not initiate, route, or authorize payment transactions
Card data received from gateway APIs is limited to masked or truncated values (e.g., last four digits)
PCI compliance responsibility for payment processing remains with your payment gateway and acquiring bank.
Platform Security
Canyon Insights follows industry-standard security practices to protect customer data.
Our approach includes
Encrypted data in transit using industry-standard encryption protocols
Encrypted data at rest within our platform
Role-based access controls and least-privilege permissions
Infrastructure hosted on Amazon Web Services (AWS), including serverless compute, S3 storage, and CloudFront content delivery, with Cloudflare routing for additional network protection
Strong password requirements enforced for all accounts, including minimum length, mixed case, numbers, and special characters
Automatic session timeouts to protect against unauthorized access on unattended devices
Data Handling & Retention
Canyon Insights follows a data-minimization approach, collecting and retaining only the data necessary to deliver reporting and analytics to your team.
