Security and trust, stated plainly
Enterprise buyers deserve precise answers, not marketing. This is Madfoa's current security, availability and compliance posture — with an explicit status for every standard.
On compliance
How we protect payments
Encryption
Data protected in transit and at rest using industry-standard cryptography.
Authentication & access
Key-based API access and least-privilege controls across environments.
Risk controls
Configurable controls applied across the transaction lifecycle.
Monitoring
Logging and monitoring to detect and investigate anomalies.
Resilient infrastructure
Cloud infrastructure designed for availability and continuity.
Business continuity
Practices designed to maintain operation and recover from disruption.
Where we stand — honestly
We do not claim certifications we do not hold. Each item below carries its current, precise status.
PCI DSS
Under assessmentScope and responsibilities depend on the deployment, provider and acquirer.
ISO 27001
PlannedAn information-security management roadmap is in progress.
SOC 2
PlannedConsidered as the platform and customer base mature.
Data residency
Customer-specificDetermined by the deployment model and regulatory environment.
Independent penetration testing
Available upon requestShared under appropriate agreements during evaluation.
Data & privacy
Data handling and residency are determined by the deployment. See our Privacy Policy and legal resources.
Availability & continuity
Infrastructure is designed for resilient operation, with routing redundancy across processing paths.
Responsible disclosure
Report a security concern to [email protected]. We appreciate coordinated disclosure.
Due diligence? Let's talk
We're glad to walk your security and procurement teams through our controls and provide documentation available upon request.