Compliance

Clear regulatory positioning: Cardencer is a technical service provider — a payment gateway — not an authorized payment institution.

Regulatory status

Cardencer provides payment gateway technology: APIs, checkout tools, fraud screening, routing, dashboards and reporting. Cardencer is not an authorized payment institution, credit institution, or e-money institution, and does not itself provide regulated payment services or hold merchant funds.

All regulated payment services — merchant acquiring, processing of funds, safeguarding, and settlement — are provided by licensed partner payment institutions supervised in their respective EU member states. The identity of the partner institution serving your account is disclosed in your merchant agreement.

PSD2 and Strong Customer Authentication

Our 3DS2 stack implements SCA under PSD2, applying exemptions (low-value, transaction risk analysis, recurring) where the acquiring institution's risk framework allows, and stepping up when the issuer requires it.

PCI DSS

Cardencer's gateway platform is assessed as a PCI DSS Level 1 service provider. Using our hosted payment page, drop-in components or mobile SDKs keeps card data out of your systems and minimises your PCI scope (SAQ A).

AML / KYC

Merchant due diligence — verification of company registration, beneficial ownership and bank account — is conducted during onboarding on behalf of, and under the requirements of, the licensed partner institutions.

Data protection

Cardencer processes personal data in accordance with the GDPR. See our Privacy Policy for details on what we process and why.