COMPLIANCE & SECURITY

Bank-Grade Compliance for High-Risk Merchants

Our compliance posture is what makes our banking partners say yes. Here's exactly how we protect merchants, partners, and consumers.

PCI DSS Compliance

BoazPay operates under PCI DSS Level 1 compliance, the highest level of the Payment Card Industry Data Security Standard. All cardholder data is handled through PCI-compliant environments. Merchants on BoazPay are never required to handle raw card numbers — tokenization ensures card data never touches merchant servers. Annual QSA audit and quarterly network scans are performed as required.

SOC 2 Type II

BoazPay maintains SOC 2 Type II certification, demonstrating that our security, availability, processing integrity, confidentiality, and privacy controls have been independently audited over an extended observation period. Reports are available to qualified prospective partners under NDA.

GDPR and CCPA Compliance

BoazPay complies with the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Merchants processing EU or California resident data under BoazPay's platform are provided Data Processing Agreements (DPAs) upon request. Our Privacy Policy governs data handling, retention, and deletion.

AML / BSA Program

BoazPay maintains a written Anti-Money Laundering / Bank Secrecy Act compliance program. Key components include: a designated BSA Compliance Officer, annual AML training for all relevant staff, risk-based transaction monitoring using automated screening tools, Suspicious Activity Report (SAR) filing procedures, and Currency Transaction Report (CTR) processes where applicable. All merchant onboarding includes AML risk assessment.

KYC / KYB Process

All merchants undergo Know Your Customer (KYC) and Know Your Business (KYB) verification at onboarding. This includes: government-issued ID verification for all beneficial owners holding 25% or greater ownership, business registration document review, beneficial ownership certification, adverse media screening, and sanctions list screening. We use automated identity verification tools supplemented by manual review for high-risk onboardings.

OFAC and Sanctions Screening

All merchants, beneficial owners, and counterparties are screened at onboarding against the OFAC SDN List, EU Consolidated Sanctions List, UN Security Council Sanctions, HM Treasury Consolidated List, and other applicable lists. Ongoing re-screening occurs on a periodic basis. Matches trigger immediate escalation to the Compliance Officer and account suspension pending review.

Data Security

All data is encrypted in transit using TLS 1.2+ (256-bit). Data at rest is encrypted using AES-256. Card data is tokenized at point of entry and never stored in plain text. Environments are segregated by function (production, staging, development). We apply the principle of least privilege for all system access. Comprehensive audit logging captures all access to sensitive systems. Penetration testing is conducted by qualified third-party firms.

Breach Notification Policy

In the event of a confirmed data breach, BoazPay will: notify affected merchants within 72 hours of confirmed breach discovery per applicable regulations, notify relevant regulators (GDPR supervisory authorities, state AGs as applicable) within regulatory timeframes, and provide affected individuals with appropriate notice within the timeframes required by applicable law. Incident response procedures are documented and tested annually.

Sponsor Bank Disclosure

BoazPay is a registered ISO/MSP of its sponsoring acquiring bank. This means BoazPay facilitates merchant account placement and processing services through sponsoring acquiring banks. BoazPay is not a bank, does not hold merchant funds, and is not FDIC-insured. All merchant processing agreements are between the merchant and the acquiring bank, with BoazPay serving as the registered agent and service provider.

Regulatory Contacts and Licenses

For regulatory inquiries, contact our Compliance Officer at compliance@boazpay.com.

Have a Compliance Question?

Contact our compliance team directly.

compliance@boazpay.com

PCI DSS Level 1

Cardholder data security

256-bit SSL

End-to-end encryption

SOC 2 Type II

Independently audited

GDPR & CCPA

Privacy compliant

BoazPay LLC is a registered ISO/MSP of its sponsoring acquiring bank.

We use cookies to improve your experience, analyze traffic, and serve relevant ads. By clicking "Accept All" you consent to our use of cookies.