Trust-center roadmap

Commerce, payment, and AI access require explicit boundaries.

The production PalSync security story will document permissions, credential storage, provider routing, evidence retention, approvals, and auditability.

Security and trust-center launch requirements

Least-privilege connections

Request only the commerce and PayPal permissions required by each supported workflow.

Write-only AI keys

Encrypt provider keys at rest, mask them after entry, and never return the raw secret.

Human approval

Stop AI-generated case content before supported submission until an authorized merchant approves.

Evidence audit trail

Record the source, model, prompt version, draft, editor, approval, submission, and outcome.

Retention controls

Explain PalSync and model-provider retention separately, including zero-retention eligibility where available.

Honest product claims

Never imply PayPal endorsement, guaranteed Seller Protection, fund release, or dispute outcomes.

DPA, subprocessors, SSO, roles, audit export, retention, and SLA.

These items must be operational and documented before the final enterprise page presents them as available.