Compliance

Compliance & certifications.

P26M is built to PCI DSS v4.0.1 requirements and is GDPR aligned. Formal certification is in progress — current documentation is available to verified merchants on request.

PCI DSS v4.0.1 ready GDPR SOC 2 — In progress
Certifications

What we hold and what we're building toward.

PCI DSS v4.0.1

In progress

Platform is built to PCI DSS v4.0.1 requirements — cardholder data storage, tokenization, network segmentation and all PSP integrations are in scope. Formal QSA assessment is under way; we are not yet certified.

GDPR

Active

EU data residency (AWS eu-central-1). Data Processing Agreement available. DPO appointed. No cross-border transfers of personal data outside the EEA.

SOC 2 Type II

In progress

Audit in progress. Expected completion Q4 2026. Covers Security, Availability, and Confidentiality trust service criteria.

ISO 27001

Planned

Planned for 2027 following SOC 2 completion. ISO 27001 controls are already partially implemented as part of our PCI DSS readiness program.

Need our AoC, SAQ, or DPA?

Attestation of Compliance, Self-Assessment Questionnaire, and Data Processing Agreements are available to verified merchants. Contact our compliance team with your request and company name.

Request documents