Skip to content

Trust center

What we do with your data, in writing

Compliance status, where data lives, who else touches it and which documents you can have today. If something you need is not here, ask for it and we will add it.

Compliance

Where each framework actually stands

Paycux is in private beta. Nothing below is certified yet, and we would rather say so on this page than in an answer to your questionnaire six weeks into an evaluation.

SOC 2 Type 2

planned

The control set on the security page is what the programme is being built around. No report exists yet.

ISO 27001

planned

Scoped as a follow-on to SOC 2. We will publish the certificate here when there is one.

GDPR

in scope

We act as a processor for our customers: data processing agreement, documented subprocessors, deletion on request, breach notification.

KVKK

in scope

Turkish data protection obligations are handled on the same basis as GDPR, including disclosure of cross-border transfers.

HIPAA

not available

We cannot sign a business associate agreement during private beta. Do not send protected health information to Paycux.

PCI DSS

not available

Paycux does not process or store cardholder data. If your integration would require that, tell us before you build it.

Data location

Where your data is processed and kept

Identity data belongs to your customers, not to us. We keep it in one place, keep it encrypted, and tell you when that changes.

  • Production data is processed and stored in an EU region during private beta; additional regions are planned and will be selectable per environment
  • Backups stay in the same region as the primary data and are encrypted with separate keys
  • Where a subprocessor operates outside that region, the transfer is covered by standard contractual clauses and listed in the data processing agreement
  • Audit events, user profiles and connection configuration are retained while the connection exists and deleted on request
  • Deletion requests reach the backups as they roll off; the retention window is stated in the data processing agreement

Subprocessors

Who else touches the data

We keep the list short on purpose. Each entry below shows what the subprocessor is used for, what reaches it and where it operates. The current named list is part of the data processing agreement, and customers are notified before a new one starts handling their data.

PurposeData reaching itRegion
Cloud hosting and computeAll platform data, encrypted at rest and in transitEU
Managed database and object storageUser profiles, connection configuration, audit events, backupsEU
Transactional email deliveryEmail address and message content for magic links, invitations and alertsEU / US
Error monitoring and operational loggingDiagnostic metadata; payloads are scrubbed before they leave the platformEU
Customer support deskContact details and the content of the ticket you send usEU / US

Need the named list before you sign anything? Ask us and we will send the current version with the data processing agreement.

Documents

What you can have today

Published documents are one click away. The rest we send on request, usually the same day.

Security overview

Published

Encryption, access control, infrastructure, secrets management and vulnerability handling.

Responsible disclosure

Published

How to report a vulnerability, what we do with it and the rules for research.

Platform status

Published

Component-by-component availability and the incident history for the platform.

Privacy policy

Published

What we collect, why we hold it, how long it stays and how to have it removed.

Data processing agreement

On request

The processor terms, the standard contractual clauses and the named subprocessor list.

Security questionnaire

On request

A completed copy of the common questionnaires, so your review does not start from a blank sheet.

Live status

Availability, without the phone call

Component-by-component status and the incident history are public. When something is wrong we say so there first, and an advisory follows if customer data or availability was affected.

Reporting a vulnerability

Email the security team directly. We acknowledge every report within two business days and work with the reporter until the issue is closed.

  • security@paycux.com for vulnerability reports
  • Two business days to acknowledge, updates until it is closed
  • Research guidelines published on the security page

Send this page to your security reviewer

It answers most of the questionnaire before anyone opens a spreadsheet.