Least-privilege connections
Request only the commerce and PayPal permissions required by each supported workflow.
The production PalSync security story will document permissions, credential storage, provider routing, evidence retention, approvals, and auditability.
Request only the commerce and PayPal permissions required by each supported workflow.
Encrypt provider keys at rest, mask them after entry, and never return the raw secret.
Stop AI-generated case content before supported submission until an authorized merchant approves.
Record the source, model, prompt version, draft, editor, approval, submission, and outcome.
Explain PalSync and model-provider retention separately, including zero-retention eligibility where available.
Never imply PayPal endorsement, guaranteed Seller Protection, fund release, or dispute outcomes.
These items must be operational and documented before the final enterprise page presents them as available.