Security & Compliance
BINKPAY handles the parts of the stack that carry the heaviest compliance burden, so your integration can stay lightweight.
PCI DSS scope
Card data is entered exclusively on BINKPAY-hosted checkout pages. If you integrate via Hosted Checkout or Payment Links and never touch raw card numbers in your own code, your PCI scope is the minimal SAQ A — you never see, transmit, or store cardholder data.
Encryption
- In transit — TLS 1.2+ on every API and checkout connection.
- At rest — sensitive fields (API keys, tokens) are encrypted at the storage layer; secret keys are shown once and masked thereafter.
Data handling
We retain payment and customer records for the duration required by applicable financial regulation in your operating jurisdiction, and never share data across merchant accounts.
For a signed copy of our security documentation or a vendor security questionnaire, contact
Was this page helpful?
