CentralPay Documentation CentralPay Documentation
  • General information
  • Documentation
  • Developers
  • English
    • FrenchSwitch to French
CentralPay Documentation CentralPay Documentation
  • General information
  • Documentation
  • Developers
  • English
    • FrenchSwitch to French
General information
  • Folder icon closed Folder open iconContact CentralPay >
  • Folder icon closed Folder open iconCentralPay
    • Certifications and Approvals
    • Security and Hosting
    • Availability Commitments
    • Platform Development
    • CentralPay Glossary
  • Folder icon closed Folder open iconContract Templates
    • Standard Merchant
    • Partner Merchant
      • MOBSP (Orias) Declaration
    • Intermediary Merchant
      • PSP Agent Declaration (ACPR)
      • ME Distributor Declaration (ACPR)
  • Folder icon closed Folder open iconOpen a CentralPay account
    • Onboarding Path
    • Principles of Reserve
    • Terms and Conditions of Use
  • Folder icon closed Folder open iconUsing the CentralPay APIs
  • Folder icon closed Folder open iconMerchant Portal
    • Guide: My Accounts
  • Folder icon closed Folder open iconCustomer Portal
  • Folder icon closed Folder open iconOnboarding Portal
  • Folder icon closed Folder open iconRates
    • Sales Offers
    • Interchange Fees and Card Schemes
    • Support Packages
  • Folder icon closed Folder open iconLogos and visuals
    • CentralPay Logos
    • PaySecure Logos
    • Reinsurance Visuals (FR/EN)
  • Folder icon closed Folder open iconTrust Center
    • Compliance and Operational ResilienceDORA
      • FAQ – Compliance and ResilienceDORA
    • Privacy PolicyGDPR
      • Subcontractors
      • FAQ – Privacy PolicyGDPR

Compliance and Operational Resilience

Estimated reading: 11 minutes

Last updated: June 30, 2025

“Our commitment to protecting your transactions and ensuring uninterrupted service. A system that complies with European requirements for security and the continuity of financial services.”

1. Governance and Security Organization

At CentralPay, security is not just a set of technical rules, but a governance approach integrated at every level of the company. Our system is based on a clear organizational structure, defined responsibilities, and regular oversight by management.

The security policy forms the foundation of this system. It establishes the guiding principles for data protection and service continuity. Updated annually, it is approved by the executive committee and distributed to all relevant employees. Each employee is thus made aware of best practices and commits to complying with the established rules.

ICT governance is structured around several key stakeholders. The Chief Information Security Officer (CISO) leads the overall strategy, oversees security controls, and ensures compliance with international standards (PCI DSS, DORA). The technical department is responsible for the day-to-day operation of the infrastructure and ensures the availability of critical systems. Finally, an IT Committee meets regularly to analyze incidents, approve technical and budgetary changes, and ensure continuous improvement in security.

This organizational structure allows us to balance operational responsiveness with regulatory requirements. It also provides our customers with clear visibility: security is monitored, managed, and controlled in a documented manner, with responsibilities shared among management, technical teams, and senior leadership.

2. Access Management and Authorizations

Access management is one of the cornerstones of CentralPay’s security. Each access right is granted according to a formalized procedure approved by management, to ensure that it strictly corresponds to the employee’s business needs. When a new employee joins the company, their access rights are created in Active Directory and approved by their supervisor; upon departure, they are immediately revoked by the IT department.

Security is also based on the principle of least privilege: no one may access more resources than are strictly necessary for their duties. Sensitive access, such as access to critical systems or databases, is systematically subject to multi-factor authentication (MFA). To strengthen this system, periodic reviews of access permissions are conducted every quarter to identify and correct any anomalies.

This rigorous approach ensures complete control over identities and access rights, and protects our customers from any risk of unauthorized access to their data.

3. Technical Safety

CentralPay’s technical security is based on an architecture designed according to the principles of defense in depth. Each layer—from the network to the applications—benefits from redundant protection mechanisms that are regularly tested.

Network Segmentation

The infrastructure is divided into several zones:

  • Public DMZ for servers exposed to the Internet (reverse proxy, WAF, SMTP relay);
  • internal zone for sensitive databases and services;
  • an administrative network reserved for administrative operations;
  • Isolated log area for collecting and analyzing logs.

Traffic between these zones is strictly controlled by redundant firewalls configured for stateful inspection and with NAT rules. These firewalls incorporate anti-spoofing mechanisms and traffic anomaly detection. The configurations are maintained by the “system and network administrators” group and are reviewed periodically.

Physical and Logical Protection

Access to the production facilities is controlled by personalized ID badges, video surveillance, and remote monitoring (SECURITAS). Access to the server rooms and the PCI area is restricted to authorized personnel.
From a logical standpoint, each system access is authenticated using a unique username, reinforced by MFA. Permissions are granted based on defined roles and in accordance with the principle of least privilege.

Surveillance and Intrusion Detection

Monitoring is carried out continuously using a combination of tools:

  • Zabbix, for real-time monitoring of servers, applications, and critical data streams;
  • Wazuh, with Snort integration, for intrusion detection and event correlation;
  • ElasticSearch/Kibana, for aggregating and visualizing logs.

Critical alerts are sent in real time to technical teams via email and text message, and their resolution is tracked in an incident log.

Encryption and Key Management

Sensitive payment data (PANs, expiration dates) is encrypted using AES-256 and rendered unreadable via a salted SHA-512 hash for comparison purposes.
Key management is performed exclusively within certified hardware security modules (HSMs). The master key is split into several components, held by different individuals, to prevent any risk of compromise. Application keys cannot be exported in plain text, and their use is strictly tracked.

By combining these measures, CentralPay ensures a robust technical environment that complies with PCI DSS 4.0.1 requirements and DORA resilience standards.

4. Risk and Incident Management

Risk management is a strategic priority for CentralPay’s governance. The approach adopted aims to anticipate threats, reduce the likelihood of their occurrence, and ensure a rapid and effective response in the event of an incident.

Risk Management

Each year, a risk assessment is conducted using the Ebios methodology, which includes Integration:

  • identifying risks related to security (intrusions, malicious attacks, data breaches) and operations (technical failures, software malfunctions);
  • their analysis in terms of probability and business impact;
  • their classification as Low, Medium, or High;
  • addressing them through preventive measures (patching, network segmentation, encryption, monitoring) or mitigation measures (workarounds, redundancies).

The risk register is updated on an ongoing basis and presented at annual management reviews.

Incident Management

CentralPay has implemented a comprehensive incident management procedure that is aligned with DORA requirements and EBA guidelines:

  • Detection: via automated monitoring (Zabbix, Wazuh) or through internal/external reports (customers, partners).
  • Classification: Each incident is analyzed and classified based on its impact, duration, geographic scope, and criticality.
  • Prioritization: An evaluation matrix (based on urgency of resolution and financial impact) is used to define priority levels ranging from 1 to 4.
  • Regulatory notification: Incidents classified as “major” must be reported to the ACPR:
    • initial report submitted within 4 hours,
    • interim report within 3 business days,
    • final report within 20 days.

Transparency and Feedback

In addition to regulatory reporting, major incidents are communicated transparently to the affected customers. A post-incident analysis is systematically conducted to identify lessons learned, strengthen existing procedures, and implement corrective actions.

This system enables CentralPay not only to respond effectively to incidents, but above all to continuously strengthen its resilience and the trust of its customers.

5. Resilience Tests

CentralPay believes that the resilience of an infrastructure is not proven solely on paper but through regular, documented tests. That is why the platform conducts various test scenarios designed to measure its security level, its disaster recovery capabilities, and the responsiveness of its teams.

Penetration Testing

Penetration tests are conducted on a regular basis by internal teams and specialized service providers to benefit from an independent external perspective. Three methodologies are used:

  • Black-box: The auditor has no prior information, which simulates the behavior of an external attacker;
  • Grey-box: The auditor has partial information (limited user accounts, simplified architecture diagrams) to simulate a realistic scenario involving a malicious user;
  • White-box: The auditor has a complete understanding of the architecture, enabling an in-depth analysis and the detection of complex vulnerabilities.

These tests cover both the network and application layers, with a particular focus on the vulnerabilities listed in the OWASP Top Ten. The results are documented in detailed reports, which include a classification of vulnerabilities by severity (Critical, High, Medium, Low) and recommendations for remediation.

Network Segmentation Tests

CentralPay also performs segmentation tests to verify that the logical partitions between zones (DMZ, internal, administration, logs) are effective and that no unauthorized traffic is possible. These tests ensure that, even if an exposed zone is compromised, the attacker cannot access critical systems.

Simulation Exercises and PCA Switches

In addition to technical tests, crisis simulation exercises are conducted. These exercises involve several teams (technical, compliance, management) and simulate attack scenarios or major outages. The goal is to test not only the robustness of the infrastructure but also the quality of coordination and communication during a crisis.

Finally, PCA switchover tests are conducted at least once a year. These tests verify that critical services can be transferred to the secondary site within the specified time frame and that the teams are fully proficient in the recovery procedures.

These various tests, which are documented and monitored, demonstrate CentralPay’s commitment to a process of continuous improvement in its resilience.

6. High Availability and Disaster Recovery Planning

The availability of payment services is an absolute requirement for CentralPay. To ensure seamless continuity, the company has designed its architecture around the principles of high availability (HA) and a multi-site Business Continuity Plan (BCP).

Multi-site architecture

CentralPay has two separate sites: a primary production site and a secondary site dedicated to the disaster recovery plan. These sites are operated by different providers, incorporate BGP routing, and use Internet connections provided by multiple carriers, which reduces the risk of dependence on a single provider.

Component Redundancy

Each critical component is deployed with redundancy:

  • Firewalls and load balancers: configured in active/active or active/passive mode, allowing for automatic failover in the event of a failure;
  • Application servers: distributed across multiple nodes to ensure fault tolerance;
  • Databases: replicated in real time between the production and disaster recovery sites, ensuring a near-zero RPO;
  • Application proxies and WAFs: deployed at the front end to handle traffic and filter out threats, with automatic failover.

Recovery Objectives (RTO and RPO)

  • RPO (Recovery Point Objective): Thanks to continuous replication, critical data can be restored to a state that is virtually identical to the one immediately prior to the incident;
  • RTO (Recovery Time Objective): Automatic failover mechanisms ensure that critical applications are back online within a few minutes to a maximum of one hour, depending on the type of component.

Failover Scenarios and Tests

The PCA is designed to address various scenarios: hardware failure, network outage, data center unavailability, and major cyberattacks. Each scenario has a documented action plan. Regular failover tests confirm that RTO/RPO commitments are met in practice.

Through this system, CentralPay assures its customers that, even in the event of a major incident, their payment transactions will remain available and secure.

7. Continuity and Backups

The continuity of CentralPay’s services does not rely solely on the redundancy of its infrastructure and its business continuity plan. It is also ensured by a strict data backup and recovery policy.

Daily, encrypted backups

Critical data—whether payment data or the platform’s operational data—is backed up daily. These backups are encrypted using AES-256, in accordance with international standards, to ensure their confidentiality in the event of unauthorized access.

Secure Storage and Rotation

Backups are stored using a redundancy and rotation system:

  • A copy is stored on internal backup servers, which are protected by restricted access;
  • A copy is moved and stored in a secure safe;
  • Other copies are stored off-site to ensure availability even in the event of a physical disaster affecting a site.

Regular rotation of storage media ensures that backups remain reliable and usable.

Restoration Tests

The value of a backup is not measured solely by its preservation but also by its ability to be restored. CentralPay therefore conducts regular restore tests, which verify not only the integrity of the backed-up data but also how quickly it can be restored to the production system.

Thanks to this approach, CentralPay ensures that, even in the event of a major incident, its customers will not suffer any significant data loss and will be able to resume their operations without prolonged disruption.

8. Management of Critical Service Providers

CentralPay recognizes that the security and continuity of its services also depend on the strength of its partners. That is why the company has implemented strict governance procedures for managing critical service providers, particularly those directly involved in hosting, data processing, or payment services.

Audits and Certifications

Each year, an audit is conducted on the primary hosting provider and service providers deemed critical. The goal is to verify the robustness of their security measures, their business continuity capabilities, and their regulatory compliance.
For service providers that process, store, or transmit card data, CentralPay requires PCI DSS certification and obtains an Attestation of Compliance (AOC) that is updated annually.

Contractual Provisions and Oversight

Contracts with critical service providers include specific DORA clauses, covering, in particular:

  • service level agreements (SLAs regarding availability and performance),
  • safety requirements,
  • the implementation of a business continuity plan (BCP) and disaster recovery plan (DRP) compatible with CentralPay’s,
  • immediate notification in the event of a security incident.

CentralPay maintains an up-to-date inventory of all its critical service providers and their associated services. This inventory is regularly updated and serves as the basis for reporting to the ACPR and other supervisory authorities.

Sustainability and Continuous Improvement

Finally, the relationship with service providers is not limited to one-time reviews. The results of audits, continuity tests, and any incidents are presented to the governance committee. Action plans are then developed to strengthen the security or availability of outsourced services.

As such, CentralPay guarantees its customers that third parties who contribute to its critical services are subject to the same standards as its own teams.

Click the links below to access the detailed pages in this section.

  • FAQ – Compliance and ResilienceDORA
Compliance and Operational Resilience - PreviousTrust CenterNext - Compliance and Operational ResilienceFAQ – Compliance and Resilience

Recently visited pages

  • Movement
  • The PAYOUT object
  • Terms and Conditions of Use
  • See more
CONTENTS

Doc Contents

Doc Footnotes

Doc Elements

  • Legal notices
  • Privacy policy

© 2026 CentralPay

You must log in to continue.

Login to CentralPay Documentation

Forgotten account?

Reset your password

Enter your username or email address and we will send you a link to reset your password.

Back to login
  • French