Company
Trust Center
Everything a procurement or compliance team asks for, in the order they ask for it. Where a fact is not confirmed yet, this page says so instead of leaving a gap.
Placeholder — not reviewed legal wording. TODO(compliance)
Cleared-pay is pre-launch. Every entity, regulatory, certification and sub-processor fact below is a placeholder until it is confirmed and signed off; none of them is a claim. Until then, Cleared-pay does not represent itself as licensed to provide payment services, certified under any standard, or registered with any card scheme.
Legal entity
Trader identification under the e-Commerce Directive. The same details appear on the imprint.
- Legal name
- TODO(compliance)operating entity
- Legal form
- TODO(compliance)company form
- Registered office
- TODO(compliance)registered address
- Commercial register and entry
- TODO(compliance)register and entry
- Company registration
- TODO(compliance)registration identifier
- VAT identifier
- TODO(compliance)VAT identifier
See also the imprint.
Regulatory status
The permission held, who supervises it, and the regulator's own register entry — so it can be checked rather than believed.
- Permission held
- TODO(compliance)permission type
- Competent authority
- TODO(compliance)supervising authority
- Authority reference
- TODO(compliance)reference in the public register
- Public register entry
- TODO(compliance)link to the regulator's own register
- Passported states
- TODO(compliance)states covered
Where Cleared-pay is not licensed
Stated explicitly, because silence on this question is worse than an answer nobody likes.
Cleared-pay holds no payment, e-money or credit permission at the time of writing, and offers no service that requires one. It does not hold client money, does not operate as a bank or a deposit-taker, and does not provide currency exchange, lending or investment services. The jurisdictions in which it is authorised, and those in which it is deliberately not, are listed here once the permissions are granted.
TODO(compliance)list of jurisdictions in and out of scopeCertifications and scheme registrations
A certification is a document with a scope and a date on it. Until that document exists, this page shows a placeholder rather than a badge.
- PCI DSS validation status
- TODO(compliance)status, assessor and validation date
- Attestation of compliance
- TODO(compliance)document and date
- ISO/IEC 27001
- TODO(compliance)certificate, scope and date
- Visa third-party agent registration
- TODO(compliance)registration status
- Mastercard registration programme
- TODO(compliance)registration status
Safeguarding of client funds
How money in flight is held, and what that protection does not extend to.
A balance held for a merchant is not a bank deposit and is not covered by a deposit guarantee scheme. The accounts used, the institutions holding them and the method applied are disclosed here and in the safeguarding statement once confirmed.
TODO(compliance)safeguarding method, accounts and institutionsSee also safeguarding of funds.
Data protection and sub-processors
Where data is processed, who processes it on our behalf, and the agreement that governs it.
- Data residency
- TODO(compliance)processing regions
- Data protection contact
- TODO(compliance)contact address
- Data processing agreement
- TODO(compliance)document to download
- Transfer mechanism
- TODO(compliance)mechanism for any transfer outside the EEA
| Purpose | Sub-processor | Processing location |
|---|---|---|
| Cloud hosting and compute | TODO(compliance)provider | TODO(compliance)region |
| Managed database | TODO(compliance)provider | TODO(compliance)region |
| Transactional email | TODO(compliance)provider | TODO(compliance)region |
| Error monitoring | TODO(compliance)provider | TODO(compliance)region |
| Customer support desk | TODO(compliance)provider | TODO(compliance)region |
See also the privacy policy.
Security practices
What the platform does today, and the assurances that are not in place yet.
- Card data never reaches a merchant server or ours in storable form: hosted fields and the hosted payment page tokenise it, and only brand, last four digits, issuing range, expiry, issuer country and a fingerprint are kept.
- Secrets are stored as hashes with a pepper and shown exactly once. A rolled key keeps working for a stated grace window so a rotation causes no failed requests.
- Webhook payloads are signed, and the signature is verified over the raw body; the reference implementation is published in the documentation.
- Two-factor authentication with a time-based code is required on the merchant portal and the internal backoffice, with an idle timeout on every session.
- Every write produces an audit entry, and every payment state change produces an event row in the same transaction as the change itself.
- Requests carry a per-response content security policy with a nonce, and the hosted payment page runs a documented script inventory for PCI DSS 6.4.3.
- Encryption at rest
- TODO(compliance)key management and rotation policy
- Penetration testing
- TODO(compliance)cadence, scope and latest test date
- Business continuity
- TODO(compliance)recovery objectives
- Personnel screening
- TODO(compliance)background-check policy
Vulnerability disclosure
If you have found something, we would rather hear it from you than from an attacker.
Report a vulnerability
Send the detail, the impact and the steps to reproduce. You get an acknowledgement, a triage decision and updates until it is fixed.
security@cleared-pay.comTODO(compliance)mailbox not live yet
Availability
Uptime is a measurement, not a promise, so it lives on a status page rather than in a headline.
- Historical uptime
- TODO(compliance)measured figure once there is traffic
- Incident history
- TODO(compliance)public incident log
Running a vendor review?
Ask for what is missing from this page. If it exists, you get the document; if it does not, you get a date.