Raw Due-Diligence Inputs
UNFORMATTEDVendor review — NovaPay Systems Inc.
SERVICE: Payment processing API for our debit card program. They tokenize and route card transactions, handle authorization requests, and store transaction-level data on behalf of the institution. We went live with them 14 months ago. Currently ~$2.1M in annual fees.
DATA ACCESS: Yes — cardholder PII (name, card number, billing address), transaction amounts/merchants, account identifiers. Counts as Critical/Tier 1 under our TPRM policy.
SOC 2 TYPE II (most recent report — period ending 9/30/2025):
- Coverage: Security, Availability, Confidentiality
- 2 exceptions noted:
(1) Patch management: 3 servers in the prod environment had OS patches delayed 47+ days beyond SLA during Q3. Auditor flagged as deviation from CC6.8.
(2) Subcontractor oversight: one sub (CloudRoute LLC) was onboarded mid-period without completing NovaPay's documented vendor assessment process. Flagged under CC9.2.
- Management response: patch process remediated per attestation; sub assessment now complete.
SECURITY QUESTIONNAIRE (completed by NovaPay, Oct 2025):
- MFA: Required for all privileged access and remote access. Standard user access still password-only in legacy admin portal (acknowledged, roadmap item Q2 2026).
- Encryption: TLS 1.3 in transit; AES-256 at rest for cardholder data. PCI-DSS Level 1 certified (AOC on file, valid thru Aug 2026).
- BCP/DR: RTO 4 hours, RPO 1 hour. Last DR test: June 2025 — partial failover test, secondary site activated. No full failover since 2023.
- Subcontractors: 4 sub-processors (CloudRoute LLC, DataVault Inc., TrustID Corp., NetMonitor AG). Only DataVault and TrustID have current SOC 2 reports on file from NovaPay. CloudRoute and NetMonitor are pending.
FINANCIAL / VIABILITY:
- Private company, ~$85M ARR, last funding round Series C ($40M, Jan 2024).
- No public financials. Per their CFO attestation, 18+ months runway.
- No insolvency proceedings, no material litigation disclosed.
PRIOR INCIDENTS:
- Aug 2024: 3.5-hour API outage affecting authorization routing. Root cause: misconfigured load balancer after a deploy. Postmortem provided; redundancy improvements deployed Nov 2024.
- No data breaches or regulatory actions disclosed.
ADDITIONAL NOTES: Contract renews Jan 2026. No SLA penalties were triggered in the past 12 months. Our team rates relationship as "satisfactory." They have not provided a right-to-audit clause — currently under negotiation.
AI-Drafted Risk Assessment
AI DRAFTED
🏢
Click "Generate Risk Assessment" to turn the raw due-diligence inputs into a structured vendor risk assessment.
⚡ Assessment completed in 38 seconds
Vendor Overview & Service
Control Assessment
| Control Domain | Rating | Key Note |
|---|---|---|
| Access Control | PARTIAL | MFA enforced for privileged/remote access; legacy admin portal remains password-only (remediation Q2 2026). Gap against FFIEC CAT and Interagency TPRM expectations for critical vendors. |
| Encryption & Data Security | SATISFACTORY | TLS 1.3 in transit, AES-256 at rest. PCI-DSS Level 1 AOC current (valid Aug 2026). Meets baseline for cardholder data environments. |
| Resilience / BCP & DR | MONITOR | RTO 4 hr / RPO 1 hr documented. Last full DR test 2023; June 2025 test was partial only. Full failover testing annually is a standard TPRM expectation for Tier 1 vendors. |
| Patch Management | EXCEPTION | SOC 2 exception: 3 prod servers patched 47+ days past SLA (CC6.8). Management attestation of remediation provided — verify in next report cycle. |
| Data Privacy | SATISFACTORY | Cardholder PII handled under PCI-DSS scope. No data breaches disclosed. Contractual data handling obligations in place; confirm GLBA-aligned data processing addendum at renewal. |
| Subcontractor Mgmt | EXCEPTION | Two of four sub-processors (CloudRoute LLC, NetMonitor AG) lack current SOC 2 reports in NovaPay's vendor file. CloudRoute onboarded without completing assessment (CC9.2 exception). Interagency Guidance §IV.C requires institutions to assess fourth-party risk for critical vendors. |
| Financial Viability | MONITOR | Private company; no audited financials. CFO attestation of 18+ months runway. Series C funded Jan 2024. Monitor concentration risk — no obvious successor/exit plan disclosed. |