Skip to content
Sandbox open: magic test cards, hosted checkout and signed webhooks · 55 payment methods in the catalogue, cards to crypto · Built and hosted in the EEA · Read the API reference at /developers

Sandbox open: magic test cards, hosted checkout and signed webhooks

Company

Trust Center

Everything a procurement or compliance team asks for, in the order they ask for it. Where a fact is not confirmed yet, this page says so instead of leaving a gap.

Placeholder — not reviewed legal wording. TODO(compliance)

Cleared-pay is pre-launch. Every entity, regulatory, certification and sub-processor fact below is a placeholder until it is confirmed and signed off; none of them is a claim. Until then, Cleared-pay does not represent itself as licensed to provide payment services, certified under any standard, or registered with any card scheme.

Trader identification under the e-Commerce Directive. The same details appear on the imprint.

Legal name
TODO(compliance)operating entity
Legal form
TODO(compliance)company form
Registered office
TODO(compliance)registered address
Commercial register and entry
TODO(compliance)register and entry
Company registration
TODO(compliance)registration identifier
VAT identifier
TODO(compliance)VAT identifier

See also the imprint.

Regulatory status

The permission held, who supervises it, and the regulator's own register entry — so it can be checked rather than believed.

Permission held
TODO(compliance)permission type
Competent authority
TODO(compliance)supervising authority
Authority reference
TODO(compliance)reference in the public register
Public register entry
TODO(compliance)link to the regulator's own register
Passported states
TODO(compliance)states covered

Where Cleared-pay is not licensed

Stated explicitly, because silence on this question is worse than an answer nobody likes.

Cleared-pay holds no payment, e-money or credit permission at the time of writing, and offers no service that requires one. It does not hold client money, does not operate as a bank or a deposit-taker, and does not provide currency exchange, lending or investment services. The jurisdictions in which it is authorised, and those in which it is deliberately not, are listed here once the permissions are granted.

TODO(compliance)list of jurisdictions in and out of scope

Certifications and scheme registrations

A certification is a document with a scope and a date on it. Until that document exists, this page shows a placeholder rather than a badge.

PCI DSS validation status
TODO(compliance)status, assessor and validation date
Attestation of compliance
TODO(compliance)document and date
ISO/IEC 27001
TODO(compliance)certificate, scope and date
Visa third-party agent registration
TODO(compliance)registration status
Mastercard registration programme
TODO(compliance)registration status

Safeguarding of client funds

How money in flight is held, and what that protection does not extend to.

A balance held for a merchant is not a bank deposit and is not covered by a deposit guarantee scheme. The accounts used, the institutions holding them and the method applied are disclosed here and in the safeguarding statement once confirmed.

TODO(compliance)safeguarding method, accounts and institutions

See also safeguarding of funds.

Data protection and sub-processors

Where data is processed, who processes it on our behalf, and the agreement that governs it.

Data residency
TODO(compliance)processing regions
Data protection contact
TODO(compliance)contact address
Data processing agreement
TODO(compliance)document to download
Transfer mechanism
TODO(compliance)mechanism for any transfer outside the EEA
Sub-processors. Each row is completed before launch and this table is versioned, so a change to the list is visible.
PurposeSub-processorProcessing location
Cloud hosting and computeTODO(compliance)providerTODO(compliance)region
Managed databaseTODO(compliance)providerTODO(compliance)region
Transactional emailTODO(compliance)providerTODO(compliance)region
Error monitoringTODO(compliance)providerTODO(compliance)region
Customer support deskTODO(compliance)providerTODO(compliance)region

See also the privacy policy.

Security practices

What the platform does today, and the assurances that are not in place yet.

  • Card data never reaches a merchant server or ours in storable form: hosted fields and the hosted payment page tokenise it, and only brand, last four digits, issuing range, expiry, issuer country and a fingerprint are kept.
  • Secrets are stored as hashes with a pepper and shown exactly once. A rolled key keeps working for a stated grace window so a rotation causes no failed requests.
  • Webhook payloads are signed, and the signature is verified over the raw body; the reference implementation is published in the documentation.
  • Two-factor authentication with a time-based code is required on the merchant portal and the internal backoffice, with an idle timeout on every session.
  • Every write produces an audit entry, and every payment state change produces an event row in the same transaction as the change itself.
  • Requests carry a per-response content security policy with a nonce, and the hosted payment page runs a documented script inventory for PCI DSS 6.4.3.
Encryption at rest
TODO(compliance)key management and rotation policy
Penetration testing
TODO(compliance)cadence, scope and latest test date
Business continuity
TODO(compliance)recovery objectives
Personnel screening
TODO(compliance)background-check policy

Vulnerability disclosure

If you have found something, we would rather hear it from you than from an attacker.

Report a vulnerability

Send the detail, the impact and the steps to reproduce. You get an acknowledgement, a triage decision and updates until it is fixed.

security@cleared-pay.comTODO(compliance)mailbox not live yet

Availability

Uptime is a measurement, not a promise, so it lives on a status page rather than in a headline.

Historical uptime
TODO(compliance)measured figure once there is traffic
Incident history
TODO(compliance)public incident log

Running a vendor review?

Ask for what is missing from this page. If it exists, you get the document; if it does not, you get a date.