Payment Orchestration Security & Compliance
Security controls for unified payments API traffic, payment routing engine operations, and merchant data protection across providers.
Security Infrastructure
Encryption
Traffic to our API, dashboard and hosted checkout is encrypted in transit with TLS.
Infrastructure
Public traffic is served through a CDN edge, internal services communicate over private networks, and production databases are backed up regularly.
Access Control
Role-based access controls (RBAC) and organization-scoped API keys with optional IP allowlisting.
Monitoring
Automated monitoring of service health, payments and payouts, with alerts routed to our operations team.
PCI DSS Practices
Payment Card Industry Standards
Card data is handled per PCI DSS (Payment Card Industry Data Security Standard) requirements, with encrypted transport and restricted access to payment data.
- Encrypted transport for card payment flows
- Access to payment data restricted by role
- 3-D Secure authentication on card payments where supported
Data Protection & Privacy
Personal Data (GDPR)
We process personal data of EU residents in line with the General Data Protection Regulation (GDPR). You can contact us to:
- • Access, correct, or delete your personal data
- • Receive a copy of your personal data
Data Retention
We retain data only as long as necessary for business operations and regulatory compliance:
- • Transaction data: 10 years (regulatory requirement)
- • Account information: Active account + 7 years
- • Audit logs: 2 years minimum
- • Marketing data: Until consent withdrawn or account closed
Data Processing
Personal data is processed securely with:
- • Encryption in transit
- • Access limited to authorized personnel only
- • Regular backups of production databases
Fraud Prevention & Risk Management
Transaction Monitoring
Real-time monitoring of transactions for suspicious patterns, velocity checks, and anomaly detection to prevent fraud before it occurs.
3D Secure Support
Support for 3D Secure (3DS) authentication including 3DS2 for enhanced security and liability shift on card transactions.
Risk Scoring
Automatic risk assessment based on transaction patterns, customer behavior, and historical data to flag high-risk transactions.
API Security
API Authentication
- Authorization header contract:
Authorization: Bearer <API_KEY> - Webhook signature verification using HMAC-SHA256
- IP whitelisting available for enhanced security
- Rate limiting to prevent abuse
Webhook Security
All webhook deliveries include security headers:
- •
X-Webhook-Signature- canonical header in the formatsha256=<hex> - •
X-Webhook-Timestamp- Timestamp to prevent replay attacks - •
X-Webhook-Id- Unique ID for deduplication
Incident Response
Security Incident Protocol
In the event of a security incident, we follow a structured response process:
- Immediate containment and assessment
- Notification to affected merchants without undue delay, and to regulators where required by law
- Transparent communication about impact and remediation
- Post-incident analysis and security improvements
To report a security vulnerability, please email [email protected] with details.
Questions About Security?
If you have specific security questions or need additional information for your compliance review, please reach out to our team.
Security Inquiries: [email protected]
We're happy to provide additional documentation, answer questions about our security practices, or discuss your specific compliance requirements.