In the financial ecosystem, “fraud” does not cover everything involved in operating securely. That's why at Pomelo we choose to talk about Risk Management as an umbrella concept that includes:
Integrated security standards
Fraud prevention tools
Technology and infrastructure
Governance and business continuity
This framework reflects how we manage risk throughout the entire operation and allows us to communicate clearly internally and to our clients.
The 4 Pillars of Risk Management at Pomelo
At Pomelo, the pillars of Risk Management are organized around four key components:
Security Standards and Fraud Prevention Tools are part of our Risk Management Platform, covering active control mechanisms and specialized solutions available to our clients.
Technology and Governance complete our offer, ensuring a secure, scalable operation with a long-term vision.
Let's examine each one of them:
1. Security Standards
These are the control mechanisms that are integrated by default into our platform. They are not contracted separately, and are active daily. They include:
Certifications such as PCI DSS
Configurable anti-fraud controls
Operational reporting and traceability
Real-time monitoring
BIN Sponsor compliance
Periodic updates and multi-region coverage
KYC/KYB according to the business model, the country, or if regulation mandates it.
These controls ensure a secure and compliant base from the start, without the need to add external layers.
These are complementary, contractable solutions designed to scale protection according to the business profile:
FICO Falcon
Dynamic CVV
3DS
Chargeback management
Push notifications: 1-way and 2-way
Specific integrations via API for authentication and prevention
These tools add depth to the client's risk strategy, adapting to their specific needs.
3. Technology
This is the foundation that allows for scaling and operating with resilience, divided into Technical Stack and Cybersecurity.
Technical Stack
Our technical stack is designed with a focus on availability, modularity, and recovery. It includes:
Multi-region infrastructure, with real regional support
Modular components that adapt without the need for code rewriting
Technological DRP (Disaster Recovery Plan): architecture prepared for extreme scenarios
Operational risk decreases drastically when technology is designed to withstand and adapt.
Cybersecurity
At Pomelo, cybersecurity is not an add-on: it is integrated into every layer of our operation. We protect our customers' information and transactions with practices aligned to the highest international standards and regulatory frameworks.
Our security pillars:
Identity and access protection with multi-factor authentication and strict permission control.
Data protection through encryption in transit and at rest, centralized management of keys and secrets in HSMs or equivalent services using AWS, and a DLP strategy backed by procedures and tools.
Application and API security with constant reviews and active monitoring.
24/7 monitoring and response through an internal RSOC that integrates NOC and SOC, ensuring timely detection, containment, and response.
Secure cloud infrastructure validated under globally recognized standards.
Certifications and compliance: PCI DSS v4, ISO 27001. We also align our strategy with both GDPR and NIST.
GDPR/LGPD, NIST, and local regulations.
With this foundation, our clients have a secure environment from day one, and the peace of mind that their information is protected under the highest market standards.
4. Governance
This pillar refers to the human, ethical, and organizational dimension of risk. It is key for large, institutional, or regulated clients. It includes:
Third Party Risk Management
Ethics and transparency: including code of ethics and whistleblowing channel
Clear and public privacy policy
Operational business continuity: processes, teams, responsibilities
Governance/GRC covering:
Compliance: PCI DSS v4, ISO 27001, GDPR/LGPD, and local
Evidence & audit: control testing and traceability
Additionally, our Legal team develops support processes that contribute to risk management:
Cross-support for contractual and regulatory risks
Regulatory compliance: ensure that decisions and policies comply with applicable laws and regulations in all markets where we operate.
Prevention of legal contingencies: identify legal risks in advance and propose alternatives and/or measures to mitigate or avoid them.
Contractual review: review and, if necessary, adjust contracts, terms, and conditions that may be impacted.
At Pomelo, Risk Management is part of how we think, design and implement financial infrastructure. Each card we launch reflects this comprehensive framework: standards that protect by default, tools that scale as needed, resilient technology, and solid governance.