Get started

Security

Security and compliance, built for moving money

Pabopay holds balances, splits payments and pays out billions of euros on behalf of platforms. That only works if every euro is protected end to end. We hold the certifications, run KYC and AML on every seller you onboard, encrypt data with HSM-backed keys, and publish the evidence in our trust center.

Certifications

Audited, certified, renewed every year

Independent assessors review our controls on a continuous basis. Current attestations and reports are available on request in the trust center below.

Card data

PCI DSS Level 1

The highest level of card-data security, assessed annually by a Qualified Security Assessor across our entire cardholder-data environment.

Controls

SOC 2 Type II

An independent report on the operating effectiveness of our security, availability and confidentiality controls over a continuous audit window.

Management

ISO 27001

A certified information security management system governing how we identify, treat and continuously reduce risk across the company.

Privacy

GDPR

EU data protection by design: lawful processing, data-subject rights, a published sub-processor list and standard contractual clauses for transfers.

Strong auth

PSD2 / SCA

Strong Customer Authentication and 3-D Secure 2 built into checkout, with exemption handling to keep conversion high where the rules allow.

Continuity

ISO 22301

A certified business continuity management system with tested disaster-recovery runbooks so payouts keep moving through disruption.

KYC / AML for sub-merchants

Every seller you onboard, verified for you

When you put a seller on your platform, Pabopay becomes the regulated layer that knows who they are. We verify each sub-merchant before a single euro moves, then keep watching for as long as they take payouts.

  • Identity verification with document and biometric liveness checks
  • Business registry and bank-account ownership confirmation
  • Ultimate beneficial owner (UBO) discovery and verification
  • Sanctions, watchlist and PEP screening against global lists
  • Ongoing transaction monitoring with risk holds and re-KYC triggers

You get a clean pass or fail and an audit-ready evidence trail. We carry the records, file the reports and refresh checks on a schedule, so onboarding a seller never turns you into a compliance department.

verification · seller #5521
IDIdentity & liveness
Verified
BRBusiness registry
Verified
UBUBO ownership
Verified
BKBank account
Verified
SCSanctions & PEP
Clear
Account status
Approved

Encryption & key management

Encrypted in transit, at rest and in use

Card numbers and account data are protected at every layer. Keys live in hardware, access is least-privilege by default, and raw card numbers never touch your systems.

  • TLS 1.3 for every connection, with HSTS and certificate pinning
  • AES-256 encryption for all data at rest, including backups
  • HSM-backed keys with automated rotation and split control
  • Card numbers tokenized — raw PANs never reach your servers
  • Least-privilege access, hardware MFA and full audit logging
key management · vault
TLSTransport
TLS 1.3Active
AESAt rest
AES-256Active
HSMKey store
FIPS 140-2Active
TOKCard numbers
TokenizedActive

Data residency & resilience

Pinned to your region, resilient by design

Choose where your data lives and trust that payouts keep flowing. We run active-active across availability zones with tested recovery and immutable backups.

Residency

Region pinning

Keep customer and payout data in the EU, US or another supported region. Data stays where you pin it, with residency guaranteed contractually.

Uptime

99.99% availability

A multi-region, active-active architecture with no single point of failure. Our public status page tracks every API and payout rail in real time.

Recovery

Disaster recovery

Cross-region failover with aggressive recovery objectives — RPO under one minute, RTO under fifteen — rehearsed in regular game-day drills.

Backups

Immutable backups

Encrypted, point-in-time backups written to write-once storage and restore-tested continuously, so the ledger can always be rebuilt intact.

Isolation

Tenant isolation

Logical isolation between platforms with scoped keys and per-tenant encryption, so one customer's data is never reachable from another's.

Monitoring

24/7 SOC

A round-the-clock security operations center with intrusion detection, anomaly alerting and a published incident-response and disclosure process.

Trust center

The evidence, on request

Vendor review or security questionnaire? Everything your team needs to assess Pabopay lives here. Reports under NDA are released in minutes, not weeks.

Attestation

SOC 2 Type II report

Request our latest SOC 2 Type II report under NDA for a full view of our controls and the auditor's opinion.

Request report
Testing

Penetration test summary

Independent firms test Pabopay at least twice a year. Download the executive summary of the most recent engagement.

Get summary
Vendors

Sub-processor list

A complete, current list of the sub-processors we rely on, what they do and where they operate. Subscribe to change notices.

View list
Live

Status page

Real-time uptime for every API, dashboard and payout rail, plus a full history of incidents and scheduled maintenance.

Open status
Questionnaires

Security questionnaires

Pre-filled CAIQ and SIG answers, plus a turnaround commitment for anything your procurement team needs in its own format.

Request pack
Disclosure

Responsible disclosure

A coordinated vulnerability-disclosure program and bug bounty. Report an issue securely and hear back from our team fast.

Report an issue
0
Platform uptime, last 12 months
0-bit
AES encryption at rest, including backups
0×/yr
Independent penetration tests
0/7
Security operations & monitoring

Bring your security team. We'll bring the evidence.

Reports, questionnaires and a walkthrough of how Pabopay protects every euro you move — we'll get your review unblocked fast.