Bank-grade by default.
Audited continuously.
PCI DSS
Level 1 Service Provider
SOC 2
Type II · annual
ISO 27001
Certified
GDPR
DPA available
DORA
EU operational resilience
99.999%
Uptime SLA · enterprise
Encryption everywhere
AES-256 at rest, TLS 1.3 in flight, PANs tokenized with hardware-backed HSM key management. Card data never touches your systems unless you ask it to.
Data stays in region
Edge authorization is global; data residency is regional. Cardholder data pinned to EU, UK, US, APAC or LATAM regions per programme.
SSO, roles & audit
SAML & OIDC SSO with SCIM provisioning, least-privilege roles per workspace, and an immutable audit log of every human and API action.
Built to keep authorizing
Active-active across regions with stand-in processing — if a region degrades, auths keep flowing at the next-nearest edge.
Attacked on purpose
Continuous automated scanning, quarterly external pentests, an always-on bug bounty, and chaos drills against the auth path itself.
Reports on request
SOC 2 report, pentest summaries, subprocessor list and uptime history — available under NDA from this page, not after three sales calls.
Send this page to your auditors.
SOC 2 report, DPA and subprocessor list — request access and we'll share under NDA today.