Meridian Alpha

Third-Party Intelligence

Entered in Prismet
Detected 3 Oct 2026
External signal
1
Security incident PG-SEC-2026-014
Dependent applications
3
use the vendor
Controls in scope
4
4 in assurance records
Actions
4
2 done · 2 open
Validated
2 of 4
response validation

Who is affected

Pulses follow recorded relationships from the event to the people who must act.
EventVendorOur applicationsControlsOwners · actionsSecurity incident PG-SEC-…External threat intelligence + …PayGate Payments Pvt. Ltd.Critical vendorPayGate Payment GatewayMerchant collection, payouts an…Meridian Customer PortalDrawdowns and settlements initi…SAP S/4HANAPayment release and settlement …VEN-03 · Supplier securit…Exception · F-RBI-03 (critical)PAY-01 · Payment APIs sec…Key rotation in progressVEN-01 · Critical third p…Penetration test report expired…PAY-02 · Payment release …OperatingAnanya RaoT-009 DoneSanjay KulkarniT-011 DoneDeepa MenonT-010 In ProgressMeera JoshiT-013 Open

Dependent applications

ApplicationDependency
PayGate Payment GatewayMerchant collection, payouts and settlement reporting
Meridian Customer PortalDrawdowns and settlements initiated by customers
SAP S/4HANAPayment release and settlement reconciliation

Controls in scope

ControlStatementRequired
VEN-03Supplier security incidents are assessed for impact and trackedException · F-RBI-03 (critical)
PAY-01Payment APIs secured with mTLS, signing and customer 2FAKey rotation in progress
VEN-01Critical third parties are risk-assessed before onboarding and annuallyPenetration test report expired · F-RBI-02
PAY-02Payment release requires maker-checkerOperating

Response actions

Actions →
ActionOwnerStatusValidation
T-009 PayGate incident impact assessment (services, apps, controls)Ananya RaoDoneValidated
T-011 File RBI / CERT-In incident notification and updateSanjay KulkarniDoneValidated
T-010 Rotate remaining PayGate settlement-report API keyDeepa MenonIn ProgressPending
T-013 Obtain PayGate 2026 penetration test summaryMeera JoshiOpenPending

Vendor tiering and exposure

Tiering
3 Critical
1 High
0 Medium
0 Low
4 vendors · criticality as recorded
Criticality × exposure
ACT FIRST02LowMediumHighCriticalOpen findings on mapped controlsAmazon Web Services (AWS India) · Critical · 1 open findings · 3 mapped controlsNorthstar BPO Services Ltd. · High · 2 open findings · 3 mapped controlsPayGate Payments Pvt. Ltd. · Critical · 2 open findings · 4 mapped controls · active signalVeriKYC Solutions Pvt. Ltd. · Critical · 2 open findings · 3 mapped controls
Bubble size = mapped controls · red = vendor with an active signal. Hover for the vendor.
VendorCriticalityService areaMapped controlsOpen findingsOpen actionsSignalsAssessment due
Amazon Web Services (AWS India)CriticalCloud service providerOPS-01, ENC-01, VEN-0111—○ No data available
Northstar BPO Services Ltd.HighBusiness process outsourcerACC-04, VEN-01, KYC-0122—○ No data available
PayGate Payments Pvt. Ltd.CriticalPayment aggregator / gatewayVEN-01, VEN-03, PAY-01, PAY-0222TPS-2026-014○ No data available
VeriKYC Solutions Pvt. Ltd.CriticalKYC / identity verification vendorVEN-02, KYC-01, KYC-0222—○ No data available