Security & Compliance
Audited by people who do not take our word for it
Card data never touches your servers and never leaves ours unencrypted. Every control below is tested annually by an external assessor.
certified
PCI DSS
Level 1
Full scope, reassessed every 12 months.
certified
SOC 2
Type II
Report available under NDA in one day.
certified
ISO
27001
Information security management system.
aligned
GDPR
& LGPD
DPA signed at onboarding, no exceptions.
02 — Residency
Your data stays where you put it
Pick a region at onboarding and transaction data never replicates outside it. Backups, logs, and analytics follow the same boundary.
sa-east-1
São Paulo
LGPD, Bacen reporting
eu-west-1
Dublin
GDPR, PSD2 SCA
us-east-1
Virginia
SOC 2, state privacy laws
ap-southeast-2
Sydney
APRA CPS 234 aligned

03 — Transparency