CentralPay Documentation CentralPay Documentation
  • General information
  • Documentation
  • Developers
  • English
    • FrenchSwitch to French
CentralPay Documentation CentralPay Documentation
  • General information
  • Documentation
  • Developers
  • English
    • FrenchSwitch to French
General information
  • Folder icon closed Folder open iconContact CentralPay >
  • Folder icon closed Folder open iconCentralPay
    • Certifications and Approvals
    • Security and Hosting
    • Availability Commitments
    • Platform Development
    • CentralPay Glossary
  • Folder icon closed Folder open iconContract Templates
    • Standard Merchant
    • Partner Merchant
      • MOBSP (Orias) Declaration
    • Intermediary Merchant
      • PSP Agent Declaration (ACPR)
      • ME Distributor Declaration (ACPR)
  • Folder icon closed Folder open iconOpen a CentralPay account
    • Onboarding Path
    • Principles of Reserve
    • Terms and Conditions of Use
  • Folder icon closed Folder open iconUsing the CentralPay APIs
  • Folder icon closed Folder open iconMerchant Portal
    • Guide: My Accounts
  • Folder icon closed Folder open iconCustomer Portal
  • Folder icon closed Folder open iconOnboarding Portal
  • Folder icon closed Folder open iconRates
    • Sales Offers
    • Interchange Fees and Card Schemes
    • Support Packages
  • Folder icon closed Folder open iconLogos and visuals
    • CentralPay Logos
    • PaySecure Logos
    • Reinsurance Visuals (FR/EN)
  • Folder icon closed Folder open iconTrust Center
    • Compliance and Operational ResilienceDORA
      • FAQ – Compliance and ResilienceDORA
    • Privacy PolicyGDPR
      • Subcontractors
      • FAQ – Privacy PolicyGDPR

FAQ – Compliance and Resilience

Estimated reading: 5 minutes

Governance and Responsibilities

Who is responsible for security at CentralPay?
Security is overseen by our CISO (Chief Information Security Officer), who reports directly to the President. The CISO relies on an ICT committee and a risk management framework aligned with ISO 27005 and the DORA regulation. The CISO can be reached at the following address: rssi@centralpay.com

Do you have a documented security policy?
Yes. Our Information System Security Policy (ISSP) defines the rules that apply to all our teams and service providers. It covers data classification, access management, system protection, incident management, business continuity, and oversight of IT service providers.

How do you integrate security into your strategic decisions?
Security and resilience are integrated into our comprehensive risk management framework. This framework includes ISO/DORA-aligned risk mapping, a risk appetite policy, and monitoring through key risk indicators (KRIs). Security decisions are reviewed by the Security & Compliance Committee and approved by senior management.

How do you monitor your security systems?
We follow the three lines of defense model: business teams perform operational controls, compliance and ongoing monitoring provide oversight, and periodic audits conduct an independent assessment.

Data and System Protection

How do you protect CentralPay’s data and systems?
All data is encrypted: TLS 1.2/1.3 for data in transit and AES-256 for data at rest. Card data is processed exclusively in a PCI DSS Level 1-certified environment and immediately tokenized, so that no full card numbers are stored in plain text.

Our infrastructure is segmented and protected by firewalls, IDS/IPS, and SOC monitoring. Access to sensitive environments is restricted, follows the principle of least privilege, and is protected by MFA. All workstations are encrypted, secured by antivirus/EDR software, and updated automatically.

Safety Tests and Inspections

Do you conduct security tests?
Yes. We regularly conduct independent penetration tests, automated vulnerability scans, and external audits (including PCI DSS). These checks help us identify vulnerabilities and continuously strengthen our security measures.

How do you handle logging?
Logs are retained for 24 months, time-stamped, protected by encryption, and integrated into our security information and event management (SIEM) system. Access to them is strictly limited to authorized teams.

How do you manage vulnerabilities and updates?
We follow a strict patch management policy: critical vulnerabilities are patched within 24 hours, high-severity vulnerabilities within 7 days, and other patches are applied on a scheduled basis. Compliance is monitored through scans and compliance reports.

Organizational Structure and Safety Culture

How do you raise your employees’ awareness of safety?
All employees undergo mandatory annual training on cybersecurity, the GDPR, and anti-money laundering and counter-terrorism financing (AML/CTF) regulations. Regular awareness campaigns (phishing exercises, e-learning) complement this program. Technical teams receive more in-depth training.

How do you ensure that access remains restricted?
We follow the principle of least privilege: each user has access only to the resources necessary for their role. Permissions are justified, temporary, and systematically tracked.

How do you manage administrator access?
Access to elevated privileges is limited to a small number of individuals, is subject to MFA, is tracked, and is reviewed regularly. Such access is granted only for specific purposes and for a limited period of time.

Proactive Planning and Continuous Improvement

How do you anticipate emerging threats?
We conduct active cybersecurity monitoring through bulletins from CERT-FR, ANSSI, software vendors, and cloud providers. This threat intelligence activity allows us to adapt our defenses in real time.

How do you continuously improve your security?
Every incident, audit, or test is followed by a documented review and a corrective action plan. Our policies and procedures are reviewed annually to integrate these lessons learned and regulatory changes.

Resilience and Continuity

How do you ensure the continuity of your services?
We have an Emergency and Business Continuity Plan (PUPA) that includes a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP). These plans are regularly tested through crisis drills and failover scenarios.

How do you ensure availability and redundancy?
Our services are based on a redundant architecture spanning multiple European regions, ensuring availability of more than 99.95%.

What are your RPO and RTO goals?
CentralPay regularly defines and tests its business continuity objectives:

  • RPO (Recovery Point Objective): less than 1 minute for critical systems, thanks to real-time data replication.
  • RTO (Recovery Time Objective): less than 15 minutes for the restoration of essential services, thanks to our redundant architecture and failover procedures.
    These objectives are validated during our business continuity and disaster recovery drills and incorporated into our DORA framework.

How do you manage your backups?
Backups are encrypted, isolated, replicated, and regularly tested to ensure they can be restored. They follow the same security policies as production environments.

Do you conduct resilience tests in accordance with DORA?
Yes. We conduct crisis exercises (simulated cyberattacks, critical outages), load and performance tests, failover scenarios, and—for critical functions—advanced tests such as TLPT (Threat-Led Penetration Testing).

Relationships with Service Providers

How do you select your critical service providers?
Each service provider undergoes due diligence (security, compliance, data location, SLA). The contracts include GDPR and DORA clauses (security, incident notification, right to audit).

How do you monitor your service providers over time?
We maintain a DORA registry that lists all of our IT service providers and identifies critical ones. These critical providers are subject to enhanced oversight, including regular reviews, audits, ISO/PCI certifications, and resilience assessments.

Incident Management

What happens in the event of a security incident?
We follow an incident management procedure that includes: detection, classification, containment, remediation, and forensic analysis. If necessary, we notify the CNIL within 72 hours and inform the affected customers. Every major incident results in a post-incident review and a corrective action plan that is monitored until the incident is closed.

FAQ – Compliance and Resilience - PreviousCompliance and Operational ResilienceNext - FAQ – Compliance and ResiliencePrivacy Policy

Recently visited pages

  • Compliance and Operational Resilience
  • See more
CONTENTS

Doc Contents

Doc Footnotes

Doc Elements

  • Legal notices
  • Privacy policy

© 2026 CentralPay

You must log in to continue.

Login to CentralPay Documentation

Forgotten account?

Reset your password

Enter your username or email address and we will send you a link to reset your password.

Back to login
  • French