Security

Written for the person who has to sign off on us: your acquirer, your lawyer, your CTO. Plain and specific. Anything not yet confirmed is marked as such.

Where your data lives
Paxora infrastructure and data are hosted in Australia (Sydney region). Data does not leave the country for processing.
Card data
Card details are tokenised in the customer’s browser and stored in an Australian-tenanted, PCI DSS Level 1 vault. Paxora never stores card numbers, and card numbers never touch Paxora servers, logs or databases. When a payment is routed, the vault presents the card to your gateway on Paxora’s behalf.
PCI position
Merchants using the Paxora drop-in field remain in the smallest PCI scope available to them. Paxora’s own self-assessment level will be stated here once confirmed with a qualified assessor; we do not publish a level before it is confirmed.
Encryption and access
All traffic is encrypted in transit. Data is encrypted at rest. Gateway credentials are held in a managed secrets store, referenced by identifier, and never written to code, configuration files or logs. Staff access is role-based, individually attributed, and logged.
Audit logging
Every payment attempt, routing decision and configuration change is written to an append-only log that cannot be edited after the fact. Merchants can read the routing decision behind any payment.
Backups and recovery
Databases have point-in-time recovery with a 35-day window plus nightly copies held in a separate account. Recovery procedures are tested before any merchant goes live.
Status and incidents
A public status page and a defined incident process, including how and when merchants are notified, are in place before the first merchant goes live. Security contact: security@paxora.com.au.

What Paxora never does

Sub-processors

A current list of sub-processors (hosting, vault, email delivery, analytics) will be published here and kept up to date. Merchants are notified before a sub-processor is added.