NMI's platform processes over $502 billion annually across 6.5 billion transactions, connecting 1.2 million active merchants through 150+ processor integrations. The attack surface is enormous: payment gateway infrastructure, EMV chip transactions, P2PE encryption pipelines, self-service payment devices, and mobile payment flows all run on a modular platform that serves ISOs, PayFacs, banks, and SaaS platforms globally.
The threat model here is concrete. Payment data in transit and at rest, device firmware integrity across 235,000+ connected endpoints, cryptographic key management for point-to-point encryption, and the trust chain between NMI's gateway and 150+ downstream processors. Merchant onboarding workflows through Merchant Central introduce additional risk vectors around identity verification and underwriting fraud. Shopping cart integrations (125+) expand the perimeter further.
Security work at this scale means building and maintaining controls across payment processing, gateway reliability, EMV certification flows, and P2PE validation - domains where a single misconfiguration can mean compromised cardholder data across millions of transactions. The company has operated since 2000, embedding payment acceptance into software platforms rather than treating it as a standalone product.






