Trust center
What we do with your data, in writing
Compliance status, where data lives, who else touches it and which documents you can have today. If something you need is not here, ask for it and we will add it.
Compliance
Where each framework actually stands
Paycux is in private beta. Nothing below is certified yet, and we would rather say so on this page than in an answer to your questionnaire six weeks into an evaluation.
SOC 2 Type 2
plannedThe control set on the security page is what the programme is being built around. No report exists yet.
ISO 27001
plannedScoped as a follow-on to SOC 2. We will publish the certificate here when there is one.
GDPR
in scopeWe act as a processor for our customers: data processing agreement, documented subprocessors, deletion on request, breach notification.
KVKK
in scopeTurkish data protection obligations are handled on the same basis as GDPR, including disclosure of cross-border transfers.
HIPAA
not availableWe cannot sign a business associate agreement during private beta. Do not send protected health information to Paycux.
PCI DSS
not availablePaycux does not process or store cardholder data. If your integration would require that, tell us before you build it.
Data location
Where your data is processed and kept
Identity data belongs to your customers, not to us. We keep it in one place, keep it encrypted, and tell you when that changes.
- Production data is processed and stored in an EU region during private beta; additional regions are planned and will be selectable per environment
- Backups stay in the same region as the primary data and are encrypted with separate keys
- Where a subprocessor operates outside that region, the transfer is covered by standard contractual clauses and listed in the data processing agreement
- Audit events, user profiles and connection configuration are retained while the connection exists and deleted on request
- Deletion requests reach the backups as they roll off; the retention window is stated in the data processing agreement
Subprocessors
Who else touches the data
We keep the list short on purpose. Each entry below shows what the subprocessor is used for, what reaches it and where it operates. The current named list is part of the data processing agreement, and customers are notified before a new one starts handling their data.
| Purpose | Data reaching it | Region |
|---|---|---|
| Cloud hosting and compute | All platform data, encrypted at rest and in transit | EU |
| Managed database and object storage | User profiles, connection configuration, audit events, backups | EU |
| Transactional email delivery | Email address and message content for magic links, invitations and alerts | EU / US |
| Error monitoring and operational logging | Diagnostic metadata; payloads are scrubbed before they leave the platform | EU |
| Customer support desk | Contact details and the content of the ticket you send us | EU / US |
Need the named list before you sign anything? Ask us and we will send the current version with the data processing agreement.
Documents
What you can have today
Published documents are one click away. The rest we send on request, usually the same day.
Security overview
PublishedEncryption, access control, infrastructure, secrets management and vulnerability handling.
Responsible disclosure
PublishedHow to report a vulnerability, what we do with it and the rules for research.
Platform status
PublishedComponent-by-component availability and the incident history for the platform.
Privacy policy
PublishedWhat we collect, why we hold it, how long it stays and how to have it removed.
Data processing agreement
On requestThe processor terms, the standard contractual clauses and the named subprocessor list.
Security questionnaire
On requestA completed copy of the common questionnaires, so your review does not start from a blank sheet.
Live status
Availability, without the phone call
Component-by-component status and the incident history are public. When something is wrong we say so there first, and an advisory follows if customer data or availability was affected.
Reporting a vulnerability
Email the security team directly. We acknowledge every report within two business days and work with the reporter until the issue is closed.
- security@paycux.com for vulnerability reports
- Two business days to acknowledge, updates until it is closed
- Research guidelines published on the security page
Send this page to your security reviewer
It answers most of the questionnaire before anyone opens a spreadsheet.