Enterprise

Pain001 for regulated teams

The software is free at any scale. What is offered around it, for teams that must show a procurement reviewer a supported path.

Verify this site’s release yourselfNo account, no NDA
  1. Fetch the release and its checksums

    gh release download -p '*' \
      -R sebastienrousseau/pain001.github.io
  2. Check every file against SHA256SUMS

    shasum -a 256 -c SHA256SUMS

    OK for every file

  3. Verify the build provenance (Sigstore)

    gh attestation verify pain001-site-*.tar.gz \
      -R sebastienrousseau/pain001.github.io

    Exit 0

Commands and results checked against the published release. The CycloneDX SBOM is also served at /sbom.cdx.json.

Evidence a reviewer can check without asking us

Every claim below resolves to an artefact you can fetch yourself. None of it requires a call, an NDA, or our word for it.

  • Bill of materials sbom.cdx.json

    CycloneDX, generated at build time and published with every deploy.

  • Release integrity Signed tags & checksums

    Every release tag is SSH-signed and ships SHA256SUMS beside the archive.

  • Build provenance Attestations

    SLSA provenance and an SBOM attestation, signed through Sigstore.

  • Supply chain posture OpenSSF Scorecard

    Scored continuously; CodeQL, Dependabot and DCO run on every change.

  • Vulnerability reporting security.txt

    A published disclosure route, not an inbox someone forwards.

  • Accessibility WCAG 2.2 AAA

    Enforced in CI across representative pages and three colour modes.

For risk and procurement

What a risk review asks. Where the answer is.

Each answer describes how the software works or what is offered on this page. None of it is a certification, and none of it replaces your own assessment.

The questionThe answerWhere to check
Where does payment data go?Nowhere. Validation runs inside your infrastructure and makes no network calls; there is no hosted service holding your files.Data handling
Can we assess the software supply chain? (DORA ICT third-party risk)A CycloneDX SBOM, signed release tags with checksums, and build provenance attested through Sigstore, all verifiable without contacting us.Evidence above
What if the maintainer stops?The source is Apache-2.0 or MIT: you can build, run and fork it indefinitely. A designated long-term-support line is available under the supported channel.Supported channel
How are defects and vulnerabilities handled?Private vulnerability reporting and a published security.txt for everyone; written response targets under the supported channel.security.txt
Does it know our bank’s rules?Not out of the box. A private profile can be derived from your bank’s guideline under NDA, without the guideline leaving your control.Private profiles

The pain001 suite is free, dual-licensed Apache-2.0 or MIT, and will stay so at any scale. That is the trust the whole project rests on, and nothing on this page changes it. What a regulated team often needs in addition is a named party with obligations: someone who answers within a window, keeps a release line stable while you are mid-migration, and can turn your bank's usage guideline into a validated profile without that guideline ever leaving your control. Those three things are offered here.

01. Supported release channel#

  • A designated long-term-support line of the core and its companions, with security fixes backported for its lifetime rather than "the latest release is the supported release".
  • Response targets for reproducible defects and security reports, in writing.
  • Release notes annotated for your context: which changes touch your rails, which are silent.

02. Private profile derivation#

  • You hold your bank's usage guideline under its licence; it never enters a public repository and never reaches this site. The library's overlay tooling inventories the guideline, diffs it against the ISO edition, and produces a profile the library enforces beside the public rail rules.
  • Delivered under NDA as a validated profile, with the derivation evidence, so your validation runs the bank's rules before the bank does.
  • Refreshed when the bank publishes a new guideline version.

03. Integration recipes#

  • End-to-end mappings from your ERP or TMS export to pain.001, with the CSV pipeline's column vocabulary, run against the example corpus for your rails until every file is clean.
  • Pipeline design for batch, streaming or API submission, with pain.002 acknowledgement handling and camt.053 reconciliation.

What this is not#

No hosted service, no telemetry, no licence change, no feature held back from the open packages. Everything a paid engagement produces that is not your bank's material flows back into the public project.

Ask#

Say which rail and country, the volume you expect, and the date you are working to. Nothing is stored beyond the message itself.







Prefer email? contact@pain001.com with "enterprise" in the subject reaches the same place.