Bank-grade by default.
Audited continuously.
PCI DSS
Level 1 Service Provider
SOC 2
Type II · annual
ISO 27001
Certified
GDPR
DPA available
DORA
EU operational resilience
99.999%
Uptime SLA · every customer
Encryption everywhere
AES-256 at rest, TLS in flight, PANs tokenized with keys held in payment HSMs. Card data never touches your systems unless you ask it to.
Data stays in the EU
Cardholder data is hosted in the EU under strict EU data residency, while cards are processed in every Visa and Mastercard region.
SSO, roles & audit
SAML and OIDC SSO, passkey sign-in, least-privilege roles per organisation and a tamper-evident audit log of every human and API action.
Built to keep authorizing
Stand-in processing and declared-exposure limits keep cards working through an outage, yours or a network's, inside limits you set.
Attacked on purpose
Continuous automated scanning and external penetration tests against the authorization path itself, not only the website.
Reports on request
SOC 2 report, penetration test summaries, DPA and subprocessor list, shared under NDA from this page rather than after three sales calls.
Send this page to your auditors.
SOC 2 report, DPA and subprocessor list: request access and we share them under NDA the same day.