Skip to content

Trust center

What we do with your data, in writing

Compliance status, where data lives, who else touches it and which documents you can have today. If something you need is not here, ask for it and we will add it.

Compliance

Where each framework actually stands

Paycux is in private beta. Nothing below is certified yet, and we would rather say so on this page than in an answer to your questionnaire six weeks into an evaluation.

SOC 2 Type 2

planned

The control set on the security page is what the programme is being built around. No report exists yet.

ISO 27001

planned

Scoped as a follow-on to SOC 2. We will publish the certificate here when there is one.

GDPR

in scope

We act as a processor for our customers: data processing agreement, documented subprocessors, deletion on request, breach notification.

KVKK

in scope

Turkish data protection obligations are handled on the same basis as GDPR, including disclosure of cross-border transfers.

HIPAA

not available

We cannot sign a business associate agreement during private beta. Do not send protected health information to Paycux.

PCI DSS

not available

Paycux does not process or store cardholder data. If your integration would require that, tell us before you build it.

Data location

Where your data is processed and kept

Identity data belongs to your customers, not to us. We keep it in one place, keep it encrypted, and tell you when that changes.

  • The hosting provider and region for production data have not been confirmed; they will be published on the subprocessors page before any data processing agreement is signed
  • Planned: backups are to stay in the same region as the primary data and be encrypted with separate keys — confirmed together with the hosting provider, not before
  • Where a subprocessor operates outside that region, the transfer is covered by standard contractual clauses and listed in the data processing agreement
  • Audit events, user profiles and connection configuration are retained while the connection exists and deleted on request
  • Deletion requests reach the backups as they roll off; the retention window is stated in the data processing agreement

Subprocessors

Who else touches the data

The vendors for each category have not been finalised, so this table lists categories rather than company names and no region is claimed until it is confirmed. It mirrors the legal subprocessors page; named vendors will be published there before any data processing agreement is signed.

PurposeData reaching itRegion
Cloud infrastructure — provider to be listedAll Subscriber Personal Data processed by the Service: hosting the application, database and backupsRegion to be confirmed
Transactional email — provider to be listedName and email address for account, sign-in and notification emailsRegion to be confirmed
Error monitoring — provider to be listedTechnical metadata; limited personal data where it appears in an errorRegion to be confirmed
Payment processing — Paddle (Merchant of Record for Paycux's own subscriptions; customers' own Stripe/Paddle accounts stay with them)Billing contact details for Paycux's own plans; payment data is handled directly by PaddleRegion to be confirmed
Customer support — provider to be listedContact details and the content of support requestsRegion to be confirmed
Product analytics — provider to be listedUsage events; pseudonymised where possibleRegion to be confirmed

The legal version of this table lives at /legal/subprocessors. Need to know before you sign anything? Ask us.

Documents

What you can have today

Published documents are one click away. The rest we send on request, usually the same day.

Security overview

Published

Encryption, access control, infrastructure, secrets management and vulnerability handling.

Responsible disclosure

Published

How to report a vulnerability, what we do with it and the rules for research.

Platform status

Published

Component-by-component availability and the incident history for the platform.

Privacy policy

Draft — under legal review

What we collect, why we hold it, how long it stays and how to have it removed. A working draft; not yet in force.

Data processing agreement

On request

The processor terms, the standard contractual clauses and the named subprocessor list.

Security questionnaire

On request

A completed copy of the common questionnaires, so your review does not start from a blank sheet.

Live status

Availability, without the phone call

Component-by-component status and the incident history are public. When something is wrong we say so there first, and an advisory follows if customer data or availability was affected.

Reporting a vulnerability

Email the security team directly. We acknowledge every report within two business days and work with the reporter until the issue is closed.

  • [email protected] for vulnerability reports
  • Two business days to acknowledge, updates until it is closed
  • Research guidelines published on the security page

Send this page to your security reviewer

It answers most of the questionnaire before anyone opens a spreadsheet.