Compliance & security
A technology provider's obligations, met as a technology provider
Our controls exist to protect payment data and platform availability. They do not, and are not intended to, substitute for the licences held by the entities within our syndicate.
Regulatory position
Euroxen holds no licence — specific syndicate entities do
Euroxen is a payment technology platform provider and does not itself hold any licence. The name Euroxen is used as a synonym for all organisations within our syndicate. Specific entities within the syndicate hold their own licences for regulated payment activities and are considered financial institutions — for details, contact us directly. Texxcor Middle East LLC provides payment gateway technology services exclusively to entities associated with our syndicate and their partners; connection to external or third-party acquirers is not an option.
Texxcor Middle East LLC is registered in Sharjah Media City (Shams), Sharjah, United Arab Emirates, and operates as a software and technical services business providing payment gateway services to entities associated with our syndicate and their partners. Where evidence of this position is required for a regulator or counterparty, we provide a written scope statement as part of the due-diligence pack. Details of the licences held by individual syndicate entities are available on direct request.
Control framework
Security and compliance controls
Certification statuses, assessment dates and report copies are shared under NDA during due diligence rather than published here.
PCI DSS scope
Cardholder data is captured, vaulted and transmitted inside a segmented environment. Hosted fields and hosted checkout let connected organisations reduce their own PCI scope.
- /Segmented CDE
- /Hosted capture options
- /Annual assessment cycle
Tokenisation
PANs are replaced with platform tokens at capture. Tokens are scoped to the connected organisation and reusable across the certified connectors of the syndicate.
- /Format-preserving tokens
- /Network token support
- /Scoped isolation
Encryption
TLS in transit with modern cipher suites, and encryption at rest for vaulted data using managed keys with documented rotation.
- /TLS 1.2+ in transit
- /AES at rest
- /Key rotation policy
Authentication & SCA
3DS2 orchestration supports strong customer authentication requirements and exemption strategies where the licensed syndicate entity permits them.
- /3DS2 flows
- /SCA exemptions
- /Authentication audit trail
Access control
Role-based access, least privilege, mandatory multi-factor authentication for platform staff and full audit logging of administrative actions.
- /RBAC
- /MFA enforced
- /Administrative audit logs
Data residency
Deployments can be pinned to a region so transaction and token data remains within the jurisdiction agreed in the contract.
- /Regional pinning
- /Documented data flows
- /Retention schedules
Continuity
Multi-region redundancy, tested backups and documented recovery objectives for the gateway and orchestration services.
- /Redundant regions
- /Tested restores
- /Defined RTO / RPO
Vendor & change control
Connector partners are assessed before certification, and platform changes follow peer review, staged release and rollback procedures.
- /Partner assessment
- /Peer-reviewed changes
- /Staged rollout
Due diligence
What we can supply on request
Typical documentation requested by regulators, counterparties and enterprise procurement teams.
- +Scope statement confirming the technology-only role and absence of licences
- +PCI DSS documentation applicable to our environment
- +Network and data-flow diagrams
- +Encryption and key management summary
- +Business continuity and recovery objectives
- +Incident response and notification process
- +Access control and personnel security policy
- +Sub-processor and vendor list
Next step
Request the due-diligence pack
Tell us which regulator, counterparty or team is reviewing us and we will send the documentation set they typically require.