Compliance
Clear regulatory positioning: Cardencer is a technical service provider — a payment gateway — not an authorized payment institution.
Regulatory status
Cardencer provides payment gateway technology: APIs, checkout tools, fraud screening, routing, dashboards and reporting. Cardencer is not an authorized payment institution, credit institution, or e-money institution, and does not itself provide regulated payment services or hold merchant funds.
All regulated payment services — merchant acquiring, processing of funds, safeguarding, and settlement — are provided by licensed partner payment institutions supervised in their respective EU member states. The identity of the partner institution serving your account is disclosed in your merchant agreement.
PSD2 and Strong Customer Authentication
Our 3DS2 stack implements SCA under PSD2, applying exemptions (low-value, transaction risk analysis, recurring) where the acquiring institution's risk framework allows, and stepping up when the issuer requires it.
PCI DSS
Cardencer's gateway platform is assessed as a PCI DSS Level 1 service provider. Using our hosted payment page, drop-in components or mobile SDKs keeps card data out of your systems and minimises your PCI scope (SAQ A).
AML / KYC
Merchant due diligence — verification of company registration, beneficial ownership and bank account — is conducted during onboarding on behalf of, and under the requirements of, the licensed partner institutions.
Data protection
Cardencer processes personal data in accordance with the GDPR. See our Privacy Policy for details on what we process and why.