Trust center
What we do with your data, in writing
Compliance status, where data lives, who else touches it and which documents you can have today. If something you need is not here, ask for it and we will add it.
Compliance
Where each framework actually stands
Paycux is in private beta. Nothing below is certified yet, and we would rather say so on this page than in an answer to your questionnaire six weeks into an evaluation.
SOC 2 Type 2
plannedThe control set on the security page is what the programme is being built around. No report exists yet.
ISO 27001
plannedScoped as a follow-on to SOC 2. We will publish the certificate here when there is one.
GDPR
in scopeWe act as a processor for our customers: data processing agreement, documented subprocessors, deletion on request, breach notification.
KVKK
in scopeTurkish data protection obligations are handled on the same basis as GDPR, including disclosure of cross-border transfers.
HIPAA
not availableWe cannot sign a business associate agreement during private beta. Do not send protected health information to Paycux.
PCI DSS
not availablePaycux does not process or store cardholder data. If your integration would require that, tell us before you build it.
Data location
Where your data is processed and kept
Identity data belongs to your customers, not to us. We keep it in one place, keep it encrypted, and tell you when that changes.
- The hosting provider and region for production data have not been confirmed; they will be published on the subprocessors page before any data processing agreement is signed
- Planned: backups are to stay in the same region as the primary data and be encrypted with separate keys — confirmed together with the hosting provider, not before
- Where a subprocessor operates outside that region, the transfer is covered by standard contractual clauses and listed in the data processing agreement
- Audit events, user profiles and connection configuration are retained while the connection exists and deleted on request
- Deletion requests reach the backups as they roll off; the retention window is stated in the data processing agreement
Subprocessors
Who else touches the data
The vendors for each category have not been finalised, so this table lists categories rather than company names and no region is claimed until it is confirmed. It mirrors the legal subprocessors page; named vendors will be published there before any data processing agreement is signed.
| Purpose | Data reaching it | Region |
|---|---|---|
| Cloud infrastructure — provider to be listed | All Subscriber Personal Data processed by the Service: hosting the application, database and backups | Region to be confirmed |
| Transactional email — provider to be listed | Name and email address for account, sign-in and notification emails | Region to be confirmed |
| Error monitoring — provider to be listed | Technical metadata; limited personal data where it appears in an error | Region to be confirmed |
| Payment processing — Paddle (Merchant of Record for Paycux's own subscriptions; customers' own Stripe/Paddle accounts stay with them) | Billing contact details for Paycux's own plans; payment data is handled directly by Paddle | Region to be confirmed |
| Customer support — provider to be listed | Contact details and the content of support requests | Region to be confirmed |
| Product analytics — provider to be listed | Usage events; pseudonymised where possible | Region to be confirmed |
The legal version of this table lives at /legal/subprocessors. Need to know before you sign anything? Ask us.
Documents
What you can have today
Published documents are one click away. The rest we send on request, usually the same day.
Security overview
PublishedEncryption, access control, infrastructure, secrets management and vulnerability handling.
Responsible disclosure
PublishedHow to report a vulnerability, what we do with it and the rules for research.
Platform status
PublishedComponent-by-component availability and the incident history for the platform.
Privacy policy
Draft — under legal reviewWhat we collect, why we hold it, how long it stays and how to have it removed. A working draft; not yet in force.
Data processing agreement
On requestThe processor terms, the standard contractual clauses and the named subprocessor list.
Security questionnaire
On requestA completed copy of the common questionnaires, so your review does not start from a blank sheet.
Live status
Availability, without the phone call
Component-by-component status and the incident history are public. When something is wrong we say so there first, and an advisory follows if customer data or availability was affected.
Reporting a vulnerability
Email the security team directly. We acknowledge every report within two business days and work with the reporter until the issue is closed.
- [email protected] for vulnerability reports
- Two business days to acknowledge, updates until it is closed
- Research guidelines published on the security page
Send this page to your security reviewer
It answers most of the questionnaire before anyone opens a spreadsheet.