Security
Payments infrastructure is only as good as its weakest control. We obsess over all of them.
Platform security
- All traffic encrypted in transit with TLS 1.2+; card data encrypted at rest.
- API keys are stored hashed — the full secret is shown exactly once at creation.
- Idempotency keys on all mutating endpoints prevent duplicate charges.
- Infrastructure hosted in EU data centres with continuous monitoring.
PCI DSS Level 1
The Cardencer gateway is assessed annually as a PCI DSS Level 1 service provider. Hosted checkout and SDK integrations keep raw card data off your servers entirely.
Fraud prevention
Machine-learned fraud scoring tuned on EU traffic, native 3DS2 with smart exemption handling, velocity checks and customisable rules — all included at no extra cost.
Responsible disclosure
Found a vulnerability? Report it to security@cardencer.eu. We respond to all reports within 48 hours and never take legal action against good-faith research.