{"id":16718,"date":"2025-10-02T09:49:11","date_gmt":"2025-10-02T07:49:11","guid":{"rendered":"https:\/\/docs.centralpay.com\/documentation\/trust-center\/compliance-and-operational-resilience\/"},"modified":"2026-09-03T09:15:13","modified_gmt":"2026-09-03T07:15:13","slug":"compliance-and-operational-resilience","status":"publish","type":"docs","link":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/","title":{"rendered":"Compliance and Operational Resilience"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Last updated: June 30, 2025<\/p>\n\n<p class=\"wp-block-paragraph\"><em>&#8220;Our commitment to protecting your transactions and ensuring uninterrupted service. A system that complies with European requirements for security and the continuity of financial services.&#8221;<\/em><\/p>\n\n<h2 class=\"wp-block-heading\">1. Governance and Security Organization<\/h2>\n\n<p class=\"wp-block-paragraph\">At CentralPay, security is not just a set of technical rules, but a governance approach integrated at every level of the company. Our system is based on a clear organizational structure, defined responsibilities, and regular oversight by management. <\/p>\n\n<p class=\"wp-block-paragraph\">The security policy forms the foundation of this system. It establishes the guiding principles for data protection and service continuity. Updated annually, it is approved by the executive committee and distributed to all relevant employees. Each employee is thus made aware of best practices and commits to complying with the established rules.   <\/p>\n\n<p class=\"wp-block-paragraph\">ICT governance is structured around several key stakeholders. The Chief Information Security Officer (CISO) leads the overall strategy, oversees security controls, and ensures compliance with international standards (PCI DSS, DORA). The technical department is responsible for the day-to-day operation of the infrastructure and ensures the availability of critical systems. Finally, an IT Committee meets regularly to analyze incidents, approve technical and budgetary changes, and ensure continuous improvement in security.   <\/p>\n\n<p class=\"wp-block-paragraph\">This organizational structure allows us to balance operational responsiveness with regulatory requirements. It also provides our customers with clear visibility: security is monitored, managed, and controlled in a documented manner, with responsibilities shared among management, technical teams, and senior leadership. <\/p>\n\n<h2 class=\"wp-block-heading\">2. Access Management and Authorizations<\/h2>\n\n<p class=\"wp-block-paragraph\">Access management is one of the cornerstones of CentralPay\u2019s security. Each access right is granted according to a formalized procedure approved by management, to ensure that it strictly corresponds to the employee\u2019s business needs. When a new employee joins the company, their access rights are created in Active Directory and approved by their supervisor; upon departure, they are immediately revoked by the IT department.  <\/p>\n\n<p class=\"wp-block-paragraph\">Security is also based on the <strong>principle of least privilege<\/strong>: no one may access more resources than are strictly necessary for their duties. Sensitive access, such as access to critical systems or databases, is systematically subject to multi-factor authentication (MFA). To strengthen this system, <strong>periodic reviews<\/strong> of access permissions are conducted every quarter to identify and correct any anomalies.  <\/p>\n\n<p class=\"wp-block-paragraph\">This rigorous approach ensures complete control over identities and access rights, and protects our customers from any risk of unauthorized access to their data.<\/p>\n\n<h2 class=\"wp-block-heading\">3. Technical Safety<\/h2>\n\n<p class=\"wp-block-paragraph\">CentralPay&#8217;s technical security is based on an architecture designed according to the principles of defense in depth. Each layer\u2014from the network to the applications\u2014benefits from redundant protection mechanisms that are regularly tested. <\/p>\n\n<h3 class=\"wp-block-heading\">Network Segmentation<\/h3>\n\n<p class=\"wp-block-paragraph\">The infrastructure is divided into several zones:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Public DMZ for servers exposed to the Internet (reverse proxy, WAF, SMTP relay);<\/li>\n\n\n\n<li>internal zone for sensitive databases and services;<\/li>\n\n\n\n<li>an administrative network reserved for administrative operations;<\/li>\n\n\n\n<li>Isolated log area for collecting and analyzing logs.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">Traffic between these zones is strictly controlled by redundant firewalls configured for stateful inspection and with NAT rules. These firewalls incorporate anti-spoofing mechanisms and traffic anomaly detection. The configurations are maintained by the \u201csystem and network administrators\u201d group and are reviewed periodically.  <\/p>\n\n<h3 class=\"wp-block-heading\">Physical and Logical Protection<\/h3>\n\n<p class=\"wp-block-paragraph\">Access to the production facilities is controlled by personalized ID badges, video surveillance, and remote monitoring (SECURITAS). Access to the server rooms and the PCI area is restricted to authorized personnel.<br\/>From a logical standpoint, each system access is authenticated using a unique username, reinforced by MFA. Permissions are granted based on defined roles and in accordance with the principle of least privilege.  <\/p>\n\n<h3 class=\"wp-block-heading\">Surveillance and Intrusion Detection<\/h3>\n\n<p class=\"wp-block-paragraph\">Monitoring is carried out continuously using a combination of tools:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Zabbix, for real-time monitoring of servers, applications, and critical data streams;<\/li>\n\n\n\n<li>Wazuh, with Snort integration, for intrusion detection and event correlation;<\/li>\n\n\n\n<li>ElasticSearch\/Kibana, for aggregating and visualizing logs.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">Critical alerts are sent in real time to technical teams via email and text message, and their resolution is tracked in an incident log.<\/p>\n\n<h3 class=\"wp-block-heading\">Encryption and Key Management<\/h3>\n\n<p class=\"wp-block-paragraph\">Sensitive payment data (PANs, expiration dates) is encrypted using AES-256 and rendered unreadable via a salted SHA-512 hash for comparison purposes.<br\/>Key management is performed exclusively within certified hardware security modules (HSMs). The master key is split into several components, held by different individuals, to prevent any risk of compromise. Application keys cannot be exported in plain text, and their use is strictly tracked.  <\/p>\n\n<p class=\"wp-block-paragraph\">By combining these measures, CentralPay ensures a robust technical environment that complies with PCI DSS 4.0.1 requirements and DORA resilience standards.<\/p>\n\n<h2 class=\"wp-block-heading\">4. Risk and Incident Management<\/h2>\n\n<p class=\"wp-block-paragraph\">Risk management is a strategic priority for CentralPay\u2019s governance. The approach adopted aims to anticipate threats, reduce the likelihood of their occurrence, and ensure a rapid and effective response in the event of an incident. <\/p>\n\n<h3 class=\"wp-block-heading\">Risk Management<\/h3>\n\n<p class=\"wp-block-paragraph\">Each year, a risk assessment is conducted using the Ebios methodology, which includes Integration:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>identifying risks related to security (intrusions, malicious attacks, data breaches) and operations (technical failures, software malfunctions);<\/li>\n\n\n\n<li>their analysis in terms of probability and business impact;<\/li>\n\n\n\n<li>their classification as Low, Medium, or High;<\/li>\n\n\n\n<li>addressing them through preventive measures (patching, network segmentation, encryption, monitoring) or mitigation measures (workarounds, redundancies).<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">The risk register is updated on an ongoing basis and presented at annual management reviews.<\/p>\n\n<h3 class=\"wp-block-heading\">Incident Management<\/h3>\n\n<p class=\"wp-block-paragraph\">CentralPay has implemented a comprehensive incident management procedure that is aligned with DORA requirements and EBA guidelines:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Detection: via automated monitoring (Zabbix, Wazuh) or through internal\/external reports (customers, partners).<\/li>\n\n\n\n<li>Classification: Each incident is analyzed and classified based on its impact, duration, geographic scope, and criticality.<\/li>\n\n\n\n<li>Prioritization: An evaluation matrix (based on urgency of resolution and financial impact) is used to define priority levels ranging from 1 to 4.<\/li>\n\n\n\n<li>Regulatory notification: Incidents classified as \u201cmajor\u201d must be reported to the ACPR:\n<ul class=\"wp-block-list\">\n<li>initial report submitted within 4 hours,<\/li>\n\n\n\n<li>interim report within 3 business days,<\/li>\n\n\n\n<li>final report within 20 days.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\">Transparency and Feedback<\/h3>\n\n<p class=\"wp-block-paragraph\">In addition to regulatory reporting, major incidents are communicated transparently to the affected customers. A post-incident analysis is systematically conducted to identify lessons learned, strengthen existing procedures, and implement corrective actions. <\/p>\n\n<p class=\"wp-block-paragraph\">This system enables CentralPay not only to respond effectively to incidents, but above all to continuously strengthen its resilience and the trust of its customers.<\/p>\n\n<h2 class=\"wp-block-heading\">5. Resilience Tests<\/h2>\n\n<p class=\"wp-block-paragraph\">CentralPay believes that the resilience of an infrastructure is not proven solely on paper but through regular, documented tests. That is why the platform conducts various test scenarios designed to measure its security level, its disaster recovery capabilities, and the responsiveness of its teams. <\/p>\n\n<h3 class=\"wp-block-heading\">Penetration Testing<\/h3>\n\n<p class=\"wp-block-paragraph\">Penetration tests are conducted on a regular basis by internal teams and specialized service providers to benefit from an independent external perspective. Three methodologies are used: <\/p>\n\n<ul class=\"wp-block-list\">\n<li>Black-box: The auditor has no prior information, which simulates the behavior of an external attacker;<\/li>\n\n\n\n<li>Grey-box: The auditor has partial information (limited user accounts, simplified architecture diagrams) to simulate a realistic scenario involving a malicious user;<\/li>\n\n\n\n<li>White-box: The auditor has a complete understanding of the architecture, enabling an in-depth analysis and the detection of complex vulnerabilities.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">These tests cover both the network and application layers, with a particular focus on the vulnerabilities listed in the OWASP Top Ten. The results are documented in detailed reports, which include a classification of vulnerabilities by severity (Critical, High, Medium, Low) and recommendations for remediation. <\/p>\n\n<h3 class=\"wp-block-heading\">Network Segmentation Tests<\/h3>\n\n<p class=\"wp-block-paragraph\">CentralPay also performs segmentation tests to verify that the logical partitions between zones (DMZ, internal, administration, logs) are effective and that no unauthorized traffic is possible. These tests ensure that, even if an exposed zone is compromised, the attacker cannot access critical systems. <\/p>\n\n<h3 class=\"wp-block-heading\">Simulation Exercises and PCA Switches<\/h3>\n\n<p class=\"wp-block-paragraph\">In addition to technical tests, crisis simulation exercises are conducted. These exercises involve several teams (technical, compliance, management) and simulate attack scenarios or major outages. The goal is to test not only the robustness of the infrastructure but also the quality of coordination and communication during a crisis.  <\/p>\n\n<p class=\"wp-block-paragraph\">Finally, PCA switchover tests are conducted at least once a year. These tests verify that critical services can be transferred to the secondary site within the specified time frame and that the teams are fully proficient in the recovery procedures. <\/p>\n\n<p class=\"wp-block-paragraph\">These various tests, which are documented and monitored, demonstrate CentralPay\u2019s commitment to a process of continuous improvement in its resilience.<\/p>\n\n<h2 class=\"wp-block-heading\">6. High Availability and Disaster Recovery Planning<\/h2>\n\n<p class=\"wp-block-paragraph\">The availability of payment services is an absolute requirement for CentralPay. To ensure seamless continuity, the company has designed its architecture around the principles of high availability (HA) and a multi-site Business Continuity Plan (BCP). <\/p>\n\n<h3 class=\"wp-block-heading\">Multi-site architecture<\/h3>\n\n<p class=\"wp-block-paragraph\">CentralPay has two separate sites: a primary production site and a secondary site dedicated to the disaster recovery plan. These sites are operated by different providers, incorporate BGP routing, and use Internet connections provided by multiple carriers, which reduces the risk of dependence on a single provider. <\/p>\n\n<h3 class=\"wp-block-heading\">Component Redundancy<\/h3>\n\n<p class=\"wp-block-paragraph\">Each critical component is deployed with redundancy:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Firewalls and load balancers: configured in active\/active or active\/passive mode, allowing for automatic failover in the event of a failure;<\/li>\n\n\n\n<li>Application servers: distributed across multiple nodes to ensure fault tolerance;<\/li>\n\n\n\n<li>Databases: replicated in real time between the production and disaster recovery sites, ensuring a near-zero RPO;<\/li>\n\n\n\n<li>Application proxies and WAFs: deployed at the front end to handle traffic and filter out threats, with automatic failover.<\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\">Recovery Objectives (RTO and RPO)<\/h3>\n\n<ul class=\"wp-block-list\">\n<li>RPO (Recovery Point Objective): Thanks to continuous replication, critical data can be restored to a state that is virtually identical to the one immediately prior to the incident;<\/li>\n\n\n\n<li>RTO (Recovery Time Objective): Automatic failover mechanisms ensure that critical applications are back online within a few minutes to a maximum of one hour, depending on the type of component.<\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\">Failover Scenarios and Tests<\/h3>\n\n<p class=\"wp-block-paragraph\">The PCA is designed to address various scenarios: hardware failure, network outage, data center unavailability, and major cyberattacks. Each scenario has a documented action plan. Regular failover tests confirm that RTO\/RPO commitments are met in practice.  <\/p>\n\n<p class=\"wp-block-paragraph\">Through this system, CentralPay assures its customers that, even in the event of a major incident, their payment transactions will remain available and secure.<\/p>\n\n<h2 class=\"wp-block-heading\">7. Continuity and Backups<\/h2>\n\n<p class=\"wp-block-paragraph\">The continuity of CentralPay&#8217;s services does not rely solely on the redundancy of its infrastructure and its business continuity plan. It is also ensured by a strict data backup and recovery policy. <\/p>\n\n<h3 class=\"wp-block-heading\">Daily, encrypted backups<\/h3>\n\n<p class=\"wp-block-paragraph\">Critical data\u2014whether payment data or the platform\u2019s operational data\u2014is backed up daily. These backups are encrypted using AES-256, in accordance with international standards, to ensure their confidentiality in the event of unauthorized access. <\/p>\n\n<h3 class=\"wp-block-heading\">Secure Storage and Rotation<\/h3>\n\n<p class=\"wp-block-paragraph\">Backups are stored using a redundancy and rotation system:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>A copy is stored on internal backup servers, which are protected by restricted access;<\/li>\n\n\n\n<li>A copy is moved and stored in a secure safe;<\/li>\n\n\n\n<li>Other copies are stored off-site to ensure availability even in the event of a physical disaster affecting a site.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">Regular rotation of storage media ensures that backups remain reliable and usable.<\/p>\n\n<h3 class=\"wp-block-heading\">Restoration Tests<\/h3>\n\n<p class=\"wp-block-paragraph\">The value of a backup is not measured solely by its preservation but also by its ability to be restored. CentralPay therefore conducts regular restore tests, which verify not only the integrity of the backed-up data but also how quickly it can be restored to the production system. <\/p>\n\n<p class=\"wp-block-paragraph\">Thanks to this approach, CentralPay ensures that, even in the event of a major incident, its customers will not suffer any significant data loss and will be able to resume their operations without prolonged disruption.<\/p>\n\n<h2 class=\"wp-block-heading\">8. Management of Critical Service Providers<\/h2>\n\n<p class=\"wp-block-paragraph\">CentralPay recognizes that the security and continuity of its services also depend on the strength of its partners. That is why the company has implemented strict governance procedures for managing critical service providers, particularly those directly involved in hosting, data processing, or payment services. <\/p>\n\n<h3 class=\"wp-block-heading\">Audits and Certifications<\/h3>\n\n<p class=\"wp-block-paragraph\">Each year, an audit is conducted on the primary hosting provider and service providers deemed critical. The goal is to verify the robustness of their security measures, their business continuity capabilities, and their regulatory compliance.<br\/>For service providers that process, store, or transmit card data, CentralPay requires PCI DSS certification and obtains an Attestation of Compliance (AOC) that is updated annually. <\/p>\n\n<h3 class=\"wp-block-heading\">Contractual Provisions and Oversight<\/h3>\n\n<p class=\"wp-block-paragraph\">Contracts with critical service providers include specific DORA clauses, covering, in particular:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>service level agreements (SLAs regarding availability and performance),<\/li>\n\n\n\n<li>safety requirements,<\/li>\n\n\n\n<li>the implementation of a business continuity plan (BCP) and disaster recovery plan (DRP) compatible with CentralPay\u2019s,<\/li>\n\n\n\n<li>immediate notification in the event of a security incident.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">CentralPay maintains an up-to-date inventory of all its critical service providers and their associated services. This inventory is regularly updated and serves as the basis for reporting to the ACPR and other supervisory authorities. <\/p>\n\n<h3 class=\"wp-block-heading\">Sustainability and Continuous Improvement<\/h3>\n\n<p class=\"wp-block-paragraph\">Finally, the relationship with service providers is not limited to one-time reviews. The results of audits, continuity tests, and any incidents are presented to the governance committee. Action plans are then developed to strengthen the security or availability of outsourced services.  <\/p>\n\n<p class=\"wp-block-paragraph\">As such, CentralPay guarantees its customers that third parties who contribute to its critical services are subject to the same standards as its own teams.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last updated: June 30, 2025 &#8220;Our commitment to protecting your transactions and ensuring uninterrupted service. A system that complies with European requirements for security and the continuity of financial services.&#8221; 1. Governance and Security Organization At CentralPay, security is not just a set of technical rules, but a governance approach integrated at every level of [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":16717,"menu_order":22,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"doc_badge":[153],"class_list":["post-16718","docs","type-docs","status-publish","hentry","doc_badge-dora","no-post-thumbnail"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Compliance and Operational Resilience - CentralPay Documentation<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Compliance and Operational Resilience - CentralPay Documentation\" \/>\n<meta property=\"og:description\" content=\"Last updated: June 30, 2025 &#8220;Our commitment to protecting your transactions and ensuring uninterrupted service. A system that complies with European requirements for security and the continuity of financial services.&#8221; 1. Governance and Security Organization At CentralPay, security is not just a set of technical rules, but a governance approach integrated at every level of [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/\" \/>\n<meta property=\"og:site_name\" content=\"CentralPay Documentation\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-03T07:15:13+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/compliance-and-operational-resilience\\\/\",\"url\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/compliance-and-operational-resilience\\\/\",\"name\":\"Compliance and Operational Resilience - CentralPay Documentation\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#website\"},\"datePublished\":\"2025-10-02T07:49:11+00:00\",\"dateModified\":\"2026-09-03T07:15:13+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/compliance-and-operational-resilience\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/compliance-and-operational-resilience\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/compliance-and-operational-resilience\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/home\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"General information\",\"item\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Trust Center\",\"item\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Compliance and Operational Resilience\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/\",\"name\":\"CentralPay Documentation\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#organization\",\"name\":\"CentralPay Documentation\",\"url\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/docs.centralpay.com\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/logo-centralpay-2023.png\",\"contentUrl\":\"https:\\\/\\\/docs.centralpay.com\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/logo-centralpay-2023.png\",\"width\":2382,\"height\":370,\"caption\":\"CentralPay Documentation\"},\"image\":{\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Compliance and Operational Resilience - CentralPay Documentation","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/","og_locale":"en_US","og_type":"article","og_title":"Compliance and Operational Resilience - CentralPay Documentation","og_description":"Last updated: June 30, 2025 &#8220;Our commitment to protecting your transactions and ensuring uninterrupted service. A system that complies with European requirements for security and the continuity of financial services.&#8221; 1. Governance and Security Organization At CentralPay, security is not just a set of technical rules, but a governance approach integrated at every level of [&hellip;]","og_url":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/","og_site_name":"CentralPay Documentation","article_modified_time":"2026-09-03T07:15:13+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/","url":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/","name":"Compliance and Operational Resilience - CentralPay Documentation","isPartOf":{"@id":"https:\/\/docs.centralpay.com\/en\/#website"},"datePublished":"2025-10-02T07:49:11+00:00","dateModified":"2026-09-03T07:15:13+00:00","breadcrumb":{"@id":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/compliance-and-operational-resilience\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/docs.centralpay.com\/en\/home\/"},{"@type":"ListItem","position":2,"name":"General information","item":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/"},{"@type":"ListItem","position":3,"name":"Trust Center","item":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/"},{"@type":"ListItem","position":4,"name":"Compliance and Operational Resilience"}]},{"@type":"WebSite","@id":"https:\/\/docs.centralpay.com\/en\/#website","url":"https:\/\/docs.centralpay.com\/en\/","name":"CentralPay Documentation","description":"","publisher":{"@id":"https:\/\/docs.centralpay.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/docs.centralpay.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/docs.centralpay.com\/en\/#organization","name":"CentralPay Documentation","url":"https:\/\/docs.centralpay.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/docs.centralpay.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/docs.centralpay.com\/wp-content\/uploads\/2023\/07\/logo-centralpay-2023.png","contentUrl":"https:\/\/docs.centralpay.com\/wp-content\/uploads\/2023\/07\/logo-centralpay-2023.png","width":2382,"height":370,"caption":"CentralPay Documentation"},"image":{"@id":"https:\/\/docs.centralpay.com\/en\/#\/schema\/logo\/image\/"}}]}},"author_avatar":"https:\/\/secure.gravatar.com\/avatar\/f26ba73d1afc0520e4b1044ff088c0eda58eeaf8c325f16e76f4f944099091cc?s=96&d=mm&r=g","author_name":"Victor","_links":{"self":[{"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs\/16718","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/comments?post=16718"}],"version-history":[{"count":1,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs\/16718\/revisions"}],"predecessor-version":[{"id":16719,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs\/16718\/revisions\/16719"}],"up":[{"embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs\/16717"}],"wp:attachment":[{"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/media?parent=16718"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/doc_tag?post=16718"},{"taxonomy":"doc_badge","embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/doc_badge?post=16718"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}