
Information Security Statement
Last updated: 20 April 2026
- ABOUT US
- GENERAL TERMS
- SERVICE SPECIFIC TERMS
- OPENPAYD PRIVACY NOTICE
- DATA PROCESSING AGREEMENT
- INFORMATION SECURITY STATEMENT
- DORA ADDENDUM FOR ICT SERVICES
The complete OpenPayd Information Security Statement is available below; alternatively, you may download and retain a copy by clicking here.
General Overview
To ensure an appropriate and proportionate level of security, we implement technical and organizational measures that take into account the nature, scope, context, and purposes of the processed data, as well as the likelihood and severity of risks to the rights and freedoms of individuals. Our technical and organizational measures aim to maintain confidentiality, integrity and availability of processed data and fulfil our regulatory and contractual obligations towards our clients. The protection of individuals is designed to be technologically neutral and does not depend on any single technology, system, or processing technique. Where appropriate, individual security controls may serve multiple protective objectives.
All technical and organizational measures implemented to maintain our technical compliance status in tact are subject to regular internal and independent audits. Robust governance, oversight, and disciplinary procedures are in place to monitor compliance, address deviations, and enforce adherence to established policies and standards.
Our processing environments, corporate infrastructure, and operational workflows are independently audited and formally certified against internationally recognized standards. These certifications demonstrate our ongoing commitment to information security, service reliability, operational excellence, and environmental responsibility.
Information Security Management System
We maintain certification to ISO/IEC 27001, confirming the implementation of a comprehensive Information Security Management System (ISMS). This framework ensures the confidentiality, integrity, and availability of information assets and enables a structured, risk-based approach to protecting customer and organizational data against evolving threats.
Payment Security
We are fully compliant with the Payment Card Industry Data Security Standard (PCI DSS) version 4.0.1. As a certified service provider, we apply rigorous controls to safeguard cardholder data, including strong authentication mechanisms, continuous monitoring, and industry-recognized encryption practices.
IT Service Management System
Our ISO/IEC 20000-1 certification validates that the quality of our IT services aligns with industry-recognized best practices, business requirements, regulatory requirements and contractual obligations. This ensures high service availability, effective incident and problem management, and a proactive, customer-focused support model.
Environmental Management System
Through ISO 14001 certification, we demonstrate our commitment to responsible and sustainable operations. Environmental risks are actively managed through efficient resource utilization and environmentally conscious operation of our physical premises and cloud infrastructure.
Pseudonymization. OpenPayd implements pseudonymization capabilities in full alignment with ISO 27001 and PCI DSS standards, ensuring high standards in processing data by maintaining confidentiality and integrity principles intact.
Encryption. As part of our ISO 27001 and PCI DSS certifications, OpenPayd maintains a rigorous encryption policy. This includes robust encryption at rest and encryption in transit, utilizing industry-recommended algorithms to ensure end-to-end data protection.
Technical Access Controls. For the purposes of ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services, OpenPayd adheres to comprehensive technical access control measures mandated by ISO 27001 and PCI DSS, which include:
- access authorization requirements;
- identification of workstation and individuals accessing OpenPayd’s systems;
- automatic disablement of accounts after multiple unsuccessful attempts for password entering;
- logging of events and activities;
- issuance and safeguarding of identification codes;
- dedicated workstations for individuals;
- authentication of authorized personnel;
- separation of production and non-production environments;
- automatic session log-off of individuals that have been inactive for a specific period;
- designation of areas in which data media may and must be located;
- designation of individuals for authorized handling and disposal of data media;
- control over disposal of data media;
- securing the areas in which data media is located and accessed from;
- controlled and documented destruction of data media;
- use of encryption where appropriate.
Data Access Controls. OpenPayd shall treat all personal data in accordance with its information assets’ classification and shall apply necessary controls to uphold the security of information assets. OpenPayd ensures that all personal data are appropriately protected against unauthorized access, corruption, loss or disclosure. OpenPayd maintains strict data access controls in line with ISO 27001, including:
- securing workstations;
- requirements for user authorization on a need-to-know basis; • appropriate confidentiality obligations;
- role-based access policies based on function and scope;
- control over destruction of data media;
- deletion of data before changing data media;
- policies controlling the production of backup copies.
Transmission Controls. OpenPayd maintains strict transmission controls as required by PCI DSS and ISO 27001, including:
- authentication of authorized personnel;
- encryption during transmission;
- documentation of transfer, retrieval, and transmission;
- malware detection and protection against malware.
Network Security. OpenPayd maintains network intrusion detection and prevention measures. OpenPayd uses all commercially reasonable efforts to ensure that its operating systems and applications are secured to mitigate the risk of security vulnerabilities in accordance with industry-recognized standards and practices and ISO 27001 security standards.
Equipment Security. OpenPayd ensures equipment security by implementing measures certified under ISO 20000-1and ISO 27001, which include:
- systems and other equipment protection to reduce the risk from environmental threats and hazards and opportunities for unauthorized access;
- maintenance of systems and other equipment to ensure its continued availability and integrity;
- protection of equipment that is power-dependent from power failures, surges and other electrical anomalies;
- implementation of exit procedures to control unauthorized removal of systems and other equipment.
- protection of all power, telecommunication and network cabling from unauthorized access and damage;
OpenPayd maintains business continuity and disaster recovery capabilities designed to minimize disruption of providing its services to the Customer in the event of a disaster or similar event. In accordance with ISO 27001 & ISO 20000-1 service level requirements, these measures include:
Annual Audited Reviews. OpenPayd performs a formal annual review and testing of its business continuity and disaster recovery plans and capabilities.
Continuous Updates. Plans are updated as needed to remain in accordance with ISO 27001 and PCI DSS generally accepted industry standards.
Data Redundancy. Implementation of secure, off-site backup solutions and redundant infrastructure to ensure high availability.
Incident Response. A dedicated incident management framework to ensure that personal data access is restored in a timely manner following any physical or technical incident.
Testing. OpenPayd has a process for regularly testing the effectiveness of technical and organizational measures as part of our ISO 27001 and PCI DSS compliance frameworks. The testing frequency is based on objective criteria, risk assessments, and regulatory requirements. OpenPayd undergoes at least an annual penetration test performed by independent security experts to identify and remediate vulnerabilities.
Assessments. OpenPayd conducts at least an annual assessment of the effectiveness of the technical and organizational measures employed. These assessments are aligned with our ISO 20000-1 service reviews and ISO 27001 internal audit requirements. OpenPayd can provide an executive summary or evidence of certification (such as an Attestation of Compliance) to Client relation to the Processed Data upon Client’s reasonable written request.
Measures for user identification and authorisation
OpenPayd has implemented appropriate measures to prevent its data processing systems from being used by unauthorized individuals, as well as to prevent unauthorized access, multiplication, alteration, deletion, or removal of personal data. In addition to the technical access controls and in compliance with ISO 27001 and PCI DSS requirements, OpenPayd has also implemented:
- maintenance of communications via secured protocols and mandatory use of multi-factor authentication (MFA) for all logical access;
- identification, verification, recording and risk assessment of external connections to networks and applications to ensure perimeter security;
- maintenance of formal password management policies and strict password confidentiality standards, including complexity and rotation requirements;
- regular access reviews to ensure that user privileges remain aligned with current roles and the “principle of least privilege.”
OpenPayd has implemented the following measures for the purposes of protection of personal data during transmission, as verified by our annual certification audits:
Use of secure channels of communications. Utilizing modern, high-strength transport layer security (TLS 1.2+) for all public and private network traffic.
Control over data media. Strict protocols for the physical and logical handling of media to prevent unauthorized data exposure.
Firewall routing. Deployment of robust network firewalls and routing policies to isolate and protect data transmission paths.
Data erasure before changing data media. Verified “wiping” or destruction of data on storage media before any change or disposal, in line with ISO 27001.
Documentation of transmissions. Maintaining comprehensive logs and audit trails of data transfers to ensure accountability.
Use of encryption where appropriate. Mandatory encryption for all sensitive data and PII moving across untrusted networks.
Authentication of authorized personnel. Ensuring that only verified users with a documented “need-to-know” can initiate or receive data transmissions.
OpenPayd has developed and implemented a vulnerability and patch management strategy supported by management controls, procedures, and operational documentation as mandated by our certifications. OpenPayd implements vulnerability mitigation, information security patches, and other relevant security vulnerability updates when available and approved to ensure secure storage of personal data or other classified information, including:
Creation of backup copies. Regular, encrypted backups to ensure data resilience and availability;
Software updates automation. Automated systems to ensure storage environments are always running the latest secure versions;
Maintenance of backup copies access management. Restricting access to backups to authorized personnel only, following the “principle of least privilege”;
Wireless networks security as per industry standards. Ensuring any administrative access via wireless networks meets PCI DSS encryption and authentication requirements;
Maintenance of retention policies. Ensuring data is only stored for as long as necessary, in compliance with ISO 27001 and legal requirements;
Personal data residency separation. Logical or physical separation of data based on residency requirements and classification;
Malware detection and protection against malware. Continuous scanning of storage environments to prevent and remediate threats;
Use of encryption where appropriate. Application of AES-256 or equivalent encryption for data at rest;
Operating system updates. Rigorous patching cycles for all servers and storage controllers to mitigate vulnerabilities.
OpenPayd maintains security standards and policies for protection of Client’s assets, data or property. OpenPayd reviews its physical security environment at least annually as part of its certified audit cycle.
OpenPayd ensures that all its personnel comply with the physical security requirements and have appropriate training in order to do so.
OpenPayd maintains access controls to ensure that only authorized personnel may enter any premises controlled by OpenPayd from which services are delivered. These access controls are verified under our ISO 27001 and PCI DSS certifications and include at a minimum:
- A robust, documented, and auditable process for issuance and removal of access credentials for personnel and third parties;
- Protection and restriction of exits to prevent unauthorized egress or tailgating;
- Personnel entry points controls, such as encrypted keycards;
- Establishment of security areas, including designated “secure zones” for sensitive data processing;
- Third parties’ entry points control, such as individual temporary keycards and mandatory visitor logging;
- Physical security of premises, including 24/7 CCTV surveillance and professional security monitoring;
- Restrictions on keys, ensuring that physical access is managed via a strict “least privilege” inventory system.
OpenPayd enables events logging on its systems that contain personal data as part of its certified security monitoring program to capture the following events:
- account logon and logoff;
- creation, modification and deletion of accounts or logon identifiers, access privileges for accounts and groups, individual rights and permissions;
- unsuccessful access attempts;
- changes in account or logon identifier status;
- account lockouts;
- modifications to, or unauthorized attempts to modify, the security configuration, security function or authorization policy.
OpenPayd captures event logs that include information for the following events:
- individual, system or process identifier that triggered the event;
- identifier of the system generating the event, which may be an IP address;
- description of the event;
- authorization information associated with the event;
- date and time the event occurred.
OpenPayd shall retain event logs for so long as necessary for providing its services, to comply with the applicable regulatory framework (including PCI DSS retention mandates), or for a longer period as it may be reasonably requested by Client. In alignment with ISO 20000-1 and ISO 27001, OpenPayd maintains industry-recognized protection of audit logs, utilizing centralized logging and write-once media where appropriate to prevent accidental or intentional modification or destruction.
OpenPayd maintains a system configuration based on industry standards, such as CIS Benchmarks. In accordance with PCI DSS and ISO 27001, OpenPayd ensures all default passwords and unnecessary services are removed or hardened before systems are deployed. OpenPayd applies security patches in accordance with its certified policies for vulnerability management.
OpenPayd shall perform all system development activities in specialized development environments, e.g., test environment, isolated from the live environment and protected against disruption and disclosure of information. OpenPayd shall ensure that systems are developed considering relevant laws and regulations as well as mitigating possible security risks through a “Security by Design” approach.
OpenPayd shall perform quality assurance of key security activities during the development lifecycle (SDLC) as required by ISO 20000-1. OpenPayd shall monitor and test its systems and shall implement fixes and developments when available and approved through a formal Change Management process.
Internal Organization Management. OpenPayd maintains an internal organization that meets—and is certified against—industry standards, including by:
- maintenance of clear allocation of responsibilities system (RACI) as required by ISO 27001 and ISO 20000-1;
- maintenance of business continuity and disaster recovery plans;
- maintenance of internal policies and procedures, guidelines, instructions, and processes
- covering data processing operations;
- maintenance of a formal “Privacy by Design” program;
- maintenance of emergency plans;
- performance of Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs).
Information Security Policies. OpenPayd maintains information security policies providing for continual assessment and re-assessment of the risks to the security of its services, in accordance with the ISO 27001 risk management framework, including:
- identification of internal threats that could result in a security breach;
- assessment of the likelihood and potential damage of internal and external threats;
- identification of external threats that could result in a security breach;
- assessment of the sufficiency of the policies, procedures, information systems and other arrangements in place, to control risks. OpenPayd’s information security policies address appropriate and detailed protection measures required for PCI DSSand ISO compliance/
Asset management. Maintaining a complete inventory of all hardware and software.
Access control. Strict identity management and authorization protocols.
Personnel security. Background checks and continuous security awareness training.
Information systems acquisition. Security requirements for development and maintenance.
Physical and environmental security. Protecting facilities in line with ISO 14001 and PCI DSS.
Information security incident management. Formal procedures for detecting and responding to events.
Communications and operations management. Securing the network and service delivery under ISO 20000-1.
OpenPayd has a program for assurance of processes and products undergoing periodic surveillance and audits to ensure that OpenPayd’s information security management system meets industry standards and best practices with due regard to the state of the art, in accordance with the risk of the categories of data processed. This program includes the maintenance and annual renewal of the following certifications:
ISO/IEC 27001. Validating our comprehensive Information Security Management System (ISMS) and risk management protocols.
ISO/IEC 20000-1. Ensuring our IT Service Management (ITSM) processes deliver reliable and consistent service quality.
ISO 14001. Confirming our Environmental Management System (EMS) meets global sustainability and corporate responsibility standards.
PCI DSS (Latest Version). Certifying that our environment meets the most stringent security requirements for the protection of cardholder data.
OpenPayd conducts regular internal audits and hosts annual external audits to ensure that these technical and organizational measures are consistently applied and improved over time.
OpenPayd’s services are designed in a manner ensuring that personal data is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. In accordance with our ISO 27001Information Security Management System and PCI DSS data retention mandates, OpenPayd strictly follows the data minimization principle during the entire personal data lifecycle in order to limit the exposure of personal data to unauthorized access. These measures include:
Privacy by Design. Integrating data minimization into the initial stages of system and service development.
Defined Retention Schedule. Automatically deleting or anonymizing data once the business or legal purpose for processing has been fulfilled.
Field-Level Minimization. Ensuring that only specific, required data fields are collected and stored within our certified environment.
OpenPayd maintains policies and procedures ensuring data quality, including any type of adjustments, erasure, or revisions to personal data. As part of our certified management systems, OpenPayd ensures data integrity through:
Validation at Entry. Implementation of automated checks and validation rules to ensure data accuracy at the point of collection.
Controlled Adjustments. Formal change management procedures for any manual revisions to data, ensuring an audit trail is maintained as required by PCI DSS.
Erasure and Rectification. Streamlined processes to ensure that requests for data correction or erasure are handled promptly and accurately across all systems.
Service Quality Monitoring. Regular data quality assessments conducted as part of our ISO 20000-1 service management reviews.
OpenPayd shall retain personal data to fulfill the purposes outlined in the Terms and the DPA in order to provide its services. OpenPayd will retain personal data in accordance with the Terms and the DPA regarding such data. OpenPayd may provide Client with controls to enable the Client to retrieve, rectify, delete or block personal data.
In accordance with its security policies and certified processes, OpenPayd shall destroy, delete, or otherwise make irrecoverable personal data:
- following the termination or expiration of the Terms or a part thereof, ensuring data is purged according to legal and ISO 27001 requirements;
- upon the disposal or repurposing of storage media containing personal data, utilizing PCI DSS compliant methods for the permanent erasure or physical destruction of hardware to prevent any data recovery.
OpenPayd maintains appropriate measures and internal policies to ensure accountability with regard to processing personal data, which are audited annually as part of our ISO and PCI DSS certifications, including but not limited to:
- maintenance of a record of all categories of processing activities carried out on behalf of the Client ensuring full traceability of data flows;
- maintenance of confidentiality policies and best practices based on a strict “need-to-know” principle, verified through regular access reviews;
- maintenance of an internal privacy program detailing the collection, processing and protection of personal data in alignment with ISO 27001 privacy controls;
- maintenance of best practices to appropriately and timely involve and provide access to information to the relevant experts on matters related to international transfers of personal data;
- maintenance of an internal information security program and policy that is reviewed, updated, and approved by management annually;
- maintenance of an external facing up-to-date privacy notice to ensure transparency with data subjects and stakeholders.
OpenPayd shall provide the Client with options for erasure in accordance with the applicable statutory and industry standard requirements. As part of our certified security management system, we ensure the following:
Logical Erasure. Utilizing industry-standard data wiping methods to ensure that personal data is irretrievable from active databases and storage systems upon request or termination.
Physical Destruction. Ensuring that any decommissioned hardware or media containing personal data is physically destroyed or degaussed in a secure environment, as verified by ISO 27001 and PCI DSS audit standards.
Verification of Deletion. Maintaining internal logs and certificates of destruction where applicable to prove that erasure has been successfully completed.
OpenPayd has ensured the following, as verified through our integrated management system and annual audits:
Availability of trained personnel. Maintaining a team of experts trained in both technical support and data protection requirements (ISO 27001) to respond to enquiries for assistance.
Effective communication channels. Deployment of redundant, secure communication platforms to ensure Client can reach support teams in accordance with ISO 20000-1 service accessibility standards.
Proactive approach to enquiries. A formal case management system that tracks assistance requests from initial receipt until their final closure, ensuring all issues are resolved to Client’s satisfaction.
Internal organization eliminating backlogs. Implementing capacity management and workflow optimization to ensure enquiries are handled in a timely manner without compromising security or service quality.
AI security controls and governance principles
A risk-based approach is applied to the secure deployment and operation of AI systems across their full lifecycle, incorporating appropriate access controls, data protection measures, and model security safeguards. This approach includes:
- documented AI policy aligned with organizational objectives, risk appetite, and regulatory obligations;
- clearly defined roles and responsibilities for AI governance, oversight, and accountability;
- third-party risk management controls, including AI-specific risk assessments and supplier due diligence prior to onboarding and throughout the relationship;
- transparent communication with stakeholders regarding the use, purpose, limitations, and impacts of AI systems;
- an AI literacy and awareness programme to ensure personnel understand AI risks, responsibilities, and secure usage practices.