• Home
    • Cashier
    • Payment Gateway
    • Hosted Payment Fields
    • Payments Solution Finder
    • Forex
    • Prop Trading
    • iGaming
    • eCommerce
    • Crypto
  • Features
  • About Us
    • Register
    • Login to Merchant Dashboard
    • Login to Partner Portal
  • Register
  • Login to Merchant Dashboard
  • Login to Partner Portal

Information Security Policy

Version 1.0 | 12 August 2026

Legal entity
PayMaxis LTD
Registration number
HE 412503
VAT number
CY10412503Y
Registered address
165, Spyrou Araouzou, Office 201A, 3036 Limassol, Cyprus
Legal / Privacy
legal@paymaxis.com
Hosting
Amazon Web Services (AWS), Ireland and Germany
Security
PCI DSS Level 1 compliant
1. Commitment
PayMaxis is committed to protecting the confidentiality, integrity and availability of information entrusted to it and to maintaining security controls appropriate to its role as a payment gateway and orchestration technology provider.
Information security is managed as an ongoing risk-management discipline that supports secure payment routing, merchant integrations, service availability, privacy obligations and the protection of payment and business information.
2. Scope
This Policy applies to PayMaxis information, systems, infrastructure, applications, networks, personnel, contractors and relevant third-party services used to deliver and support PayMaxis products and business operations. It includes systems involved in payment gateway and orchestration services and the applicable cardholder-data environment.
3. Security Objectives
  • protect the confidentiality of sensitive payment, merchant, personal and business information;
  • preserve the integrity and accuracy of systems, transactions and records;
  • maintain appropriate availability and resilience of critical services;
  • prevent, detect, respond to and learn from security incidents;
  • meet applicable contractual, legal, regulatory and payment-card security obligations;
  • manage technology and supplier risk in a structured manner;
  • continually improve security controls in response to risk, incidents, testing and evolving threats.
4. PCI DSS
PayMaxis is PCI DSS Level 1 compliant. PayMaxis maintains controls applicable to its PCI DSS scope and payment-card environment, including requirements related to secure networks and systems, protection of account data, vulnerability management, access control, monitoring and testing, and security governance.
PCI DSS compliance does not remove the independent responsibilities of merchants, acquirers, PSPs or other parties in the payment chain. Each party remains responsible for its own applicable PCI DSS scope and obligations.
5. Risk Management
PayMaxis identifies, assesses, treats and reviews information-security risks based on factors such as threat likelihood, business impact, data sensitivity, system criticality, legal obligations, payment-industry requirements and third-party dependencies. Security controls are selected and maintained using a risk-based approach.
6. Access Control and Identity Security
  • access is granted according to business need and least-privilege principles;
  • privileged access is restricted and subject to enhanced controls;
  • authentication controls are applied according to risk and system sensitivity;
  • user and access rights are reviewed and removed or changed when no longer required;
  • segregation of duties is applied where appropriate to reduce operational and security risk.
7. Data Protection and Cryptography
PayMaxis applies controls intended to protect sensitive information during transmission and storage, including encryption or equivalent safeguards where appropriate. Cardholder data is handled within the applicable PCI DSS control framework. Data minimisation, masking, tokenisation, retention controls and secure disposal are applied where relevant to the system and business purpose.
8. Secure Development and Change Management
Security is integrated into the development and change lifecycle for PayMaxis systems. Relevant changes are subject to controlled development, review, testing, deployment and rollback practices. Security requirements, code quality, dependency risk and vulnerability considerations are incorporated according to system risk and criticality.
9. Vulnerability and Patch Management
PayMaxis maintains processes to identify, assess, prioritise and remediate vulnerabilities in systems and applications. This may include vulnerability scanning, dependency and configuration review, penetration testing, security testing and timely application of security patches according to risk.
10. Logging, Monitoring and Detection
Relevant systems and security events are logged and monitored to support operational oversight, fraud prevention, anomaly detection, forensic investigation and incident response. Log access and retention are controlled according to operational, security, evidential and legal needs.
11. Incident Management
PayMaxis maintains incident-management procedures covering detection, triage, containment, investigation, eradication, recovery, evidence preservation, internal escalation, lessons learned and communication. Security and personal-data breaches are assessed for notification obligations under applicable law, contract and payment-industry requirements.
12. Business Continuity and Disaster Recovery
PayMaxis maintains business-continuity and disaster-recovery arrangements proportionate to the criticality of its services. These arrangements are intended to support resilience, recovery of critical capabilities and appropriate response to disruptive events. Plans and recovery procedures are reviewed and tested periodically.
13. Cloud and Infrastructure Security
PayMaxis uses Amazon Web Services (AWS) infrastructure in Ireland and Germany. Cloud security responsibilities are managed according to the shared-responsibility model, with PayMaxis responsible for configuring and securing the applications, identities, data, networks and services within its control and AWS responsible for security of the underlying cloud infrastructure according to the services used.
14. Third-Party and Supplier Security
Suppliers and service providers with access to PayMaxis information or systems are subject to security and risk considerations appropriate to the service provided. PayMaxis may use due diligence, contractual controls, security reviews, compliance evidence and ongoing monitoring to manage supplier risk.
15. Personnel Security and Awareness
Personnel with access to PayMaxis systems or information are required to follow applicable security policies and confidentiality obligations. PayMaxis provides security awareness and role-appropriate guidance or training and maintains processes for managing access when personnel join, change roles or leave.
16. Compliance, Review and Improvement
PayMaxis reviews its information-security arrangements periodically and when material changes, incidents, new threats or compliance obligations arise. Findings from testing, monitoring, audits, risk assessments and incidents are used to drive corrective action and continual improvement.
Contact

Questions, requests or concerns regarding this policy may be addressed to:

PayMaxis LTD

165, Spyrou Araouzou, Office 201A, 3036 Limassol, Cyprus

Email: legal@paymaxis.com

Terms and Conditions
•
Privacy Policy
•
Cookies Settings
•
Information Security Policy
•
Client Acceptance Policy
Products
Cashier
Payment Gateway
Hosted Payment Fields
Payments Solution Finder
Industries
Forex
Prop Trading
iGaming
Crypto
eCommerce
Features
Smart Routing & Retry
Dynamic Currency Conversion
Customized Checkout
Network Tokenization
Hosted Fields
One Unified API
Company
Company
Contact Us
Book a Demo
Developers
API Documentation
Certificates
PCI DSS Level 1 Certificate
Visa Verified Service Provider
PayMaxis provides payment technology and orchestration services. Payment processing, acquiring, settlement and other regulated payment services are provided by appropriately authorised third-party payment providers, where applicable. PayMaxis does not hold client funds.