Enterprise-Level Security

Customer payment data. Never your liability.

Alternative Payments is SOC 2 Type 2 certified, PCI-DSS Level 1 compliant, and built on AWS. Card numbers are tokenized the moment they are captured. Our security team runs the controls every day, not just at audit time.

Book a demo
A professional at a laptop surrounded by security icons representing encryption and access control
Trusted by 1,000+ service businesses nationwide

Top-notch security features

Strict access controls

Compliance monitoring

Regular security audits

Protocol adherence

Protecting you and your customers.

Payment data is tokenized at capture, encrypted in transit via TLS 1.2 or higher, and never stored on systems your team can access. Access is role-based, with four permission levels scoped to what each team member actually needs. MFA is available on both the partner dashboard and the Customer Portal.

The certifications, and the work behind them.

Compliance is not a logo on a page. It is a posture our team maintains every day. Two standards your auditors will ask about.

PCI Security Standards Council compliance logo

PCI-DSS Level 1 compliance

The highest level of payment card security available. Card data is tokenized at capture and routed directly to the card networks. Card numbers never sit on your systems. Your PCI scope shrinks the day you connect.

AICPA SOC for Service Organizations compliance logo

SOC 2 Type 2 compliance

An independent third-party audit of our security, availability, and confidentiality controls, refreshed every year. The full report is available under NDA. Your CISO can read it before you sign.

Frequently Asked Questions

Several layers working together. Card numbers are tokenized at capture and never touch your systems. Data is encrypted in transit via TLS 1.2 or higher, and at rest. Access is role-based across four permission levels, logged, and protected by MFA. Our security team monitors continuously and runs incident response on call.

PCI-DSS is the security standard every company that handles credit card data must meet. Alternative Payments is certified at Level 1, the highest tier, which means we have been independently audited against the full standard. When you process through Alternative Payments, the scope of your own PCI obligations shrinks, because the sensitive data never lives on your side.

SOC 2 Type 2 is an independent audit of how a company operates its security, availability, and confidentiality controls over a sustained period. Type 2 means the auditor verified the controls were working over time, not just on a single day. Alternative Payments completes a SOC 2 Type 2 audit every year. The full report is available under NDA.

Yes, when it is built right. Alternative Payments runs on Amazon Web Services, which is itself SOC 2, ISO 27001, and PCI-DSS-certified. We layer our own controls on top: tokenization, encryption via TLS 1.2 or higher, role-based access across four permission levels, MFA, and continuous monitoring. The result is a stronger security posture than most service businesses could build on their own.

Card numbers are tokenized at capture. The actual card number is replaced with a token and routed directly to the card networks. Your team never sees the full number. We never store the full number. If our system were breached, there is no usable card data to take.

Yes. MFA is available on both the partner dashboard and the Customer Portal. Partners and their customers can set it up using any TOTP-compatible authenticator app, including Google Authenticator, Microsoft Authenticator, Authy, and 1Password.

Keep reading

View all

See the security posture your CISO will sign off on.

Book a demo to walk through the controls, see the audit reports, and meet the team behind them.

Book a demo