Security & trust

Protected by design.

Bank-grade security and compliance built into every layer of MondialPay. Your customers' data and funds are protected by the same standards used by the world's largest financial institutions.

Certifications

Compliance you can verify

We hold every certification a modern payment processor needs — and we audit annually.

PCI DSS Level 1

The highest level of card data security certification.

ISO 27001

Internationally-recognised information security management.

SOC 2 Type II

Continuous audit of our operational security controls.

GDPR

EU data protection, with data residency options.

Defence in depth

Security at every layer

We don't rely on a single line of defence. Every piece of the MondialPay stack is designed to contain and detect issues independently.

  • End-to-end encryption in transit (TLS 1.3) and at rest (AES-256)
  • Tokenization — raw card details never touch your servers
  • 3D Secure 2, device fingerprinting, and ML-based fraud detection
  • 24/7 security operations centre and automated threat monitoring
  • Annual external penetration testing and public bug bounty
Layered security illustration
99.999%
SLA-backed uptime
256-bit
AES at rest
24/7
Security operations
$50K
Bug bounty maximum
Defence in depth

Security at every layer

Encryption, tokenisation, network segmentation, fraud ML, audit logging — every layer designed to fail safely.

SOC 2 · ISO 27001 · PCI L1

Continuous monitoring across every region

Deep dive

How we keep your data safe

The mechanisms behind every claim above — we publish what we do so you can verify it.

Encryption & tokenisation

TLS 1.3 in transit, AES-256 at rest, and per-customer envelope encryption with keys held in HSMs. Card numbers are tokenised the moment they enter our network — your servers never see raw PANs.

Network & infrastructure

Multi-region active-active deployments behind hardened load balancers. WAF, DDoS protection, micro-segmented service mesh, and zero-trust internal networking. Production access requires hardware MFA.

Continuous monitoring & incident response

24/7 security operations centre with automated detection and on-call response. Quarterly red-team exercises, public bug bounty up to $50K, and a published incident response playbook.

Audits & reports available on request

SOC 2 Type II, ISO 27001 certificate, PCI DSS AoC, latest pen-test summary, and our DPA are all available under NDA via the Trust Centre. Our DPO answers customer questionnaires within 5 business days.

Security questionnaire?

Send it to security@mondialpay.com — most go round-trip in under 5 business days. SOC 2 reports and DPAs are pre-filled and ready to share.