Protected by design.
Bank-grade security and compliance built into every layer of MondialPay. Your customers' data and funds are protected by the same standards used by the world's largest financial institutions.
Compliance you can verify
We hold every certification a modern payment processor needs — and we audit annually.
PCI DSS Level 1
The highest level of card data security certification.
ISO 27001
Internationally-recognised information security management.
SOC 2 Type II
Continuous audit of our operational security controls.
GDPR
EU data protection, with data residency options.
Security at every layer
We don't rely on a single line of defence. Every piece of the MondialPay stack is designed to contain and detect issues independently.
- End-to-end encryption in transit (TLS 1.3) and at rest (AES-256)
- Tokenization — raw card details never touch your servers
- 3D Secure 2, device fingerprinting, and ML-based fraud detection
- 24/7 security operations centre and automated threat monitoring
- Annual external penetration testing and public bug bounty
Security at every layer
Encryption, tokenisation, network segmentation, fraud ML, audit logging — every layer designed to fail safely.
Continuous monitoring across every region
How we keep your data safe
The mechanisms behind every claim above — we publish what we do so you can verify it.
Encryption & tokenisation
TLS 1.3 in transit, AES-256 at rest, and per-customer envelope encryption with keys held in HSMs. Card numbers are tokenised the moment they enter our network — your servers never see raw PANs.
Network & infrastructure
Multi-region active-active deployments behind hardened load balancers. WAF, DDoS protection, micro-segmented service mesh, and zero-trust internal networking. Production access requires hardware MFA.
Continuous monitoring & incident response
24/7 security operations centre with automated detection and on-call response. Quarterly red-team exercises, public bug bounty up to $50K, and a published incident response playbook.
Audits & reports available on request
SOC 2 Type II, ISO 27001 certificate, PCI DSS AoC, latest pen-test summary, and our DPA are all available under NDA via the Trust Centre. Our DPO answers customer questionnaires within 5 business days.