Is Easy Pay Direct PCI DSS compliant?
Yes. Easy Pay Direct's payment platform has been independently assessed for PCI DSS compliance by Coalfire Systems, a Qualified Security Assessor (QSA). Our compliance posture is maintained through a current Report on Compliance (RoC) or Self-Assessment Questionnaire (SAQ), updated annually, and we operate to PCI DSS Level 1 standards for our scope of the cardholder data environment.
How does Easy Pay Direct encrypt card data?
Card data is encrypted in transit with TLS 1.2 or higher and protected by a 256-bit DigiCert SSL certificate. At point of entry, card numbers are tokenized so raw PAN data never touches your servers or ours in a recoverable form at rest. Stored data is encrypted with AES-256. We never store CVV2, and we never store track data from card swipes.
Does Easy Pay Direct run AML and KYC checks?
Yes. Every applicant and every beneficial owner is run through a formal Anti-Money-Laundering and Know-Your-Customer process at onboarding. We collect documentation, verify identity, validate business legitimacy, and refresh the file on a defined schedule. AML and KYC are not deferred until volume scales, they happen upfront.
Do you screen applicants against OFAC and sanctions lists?
Yes. Every applicant, beneficial owner, and key principal is screened against OFAC, the Specially Designated Nationals (SDN) list, and global sanctions databases at onboarding. Screening is refreshed on an ongoing basis to catch newly added entries.
How does Easy Pay Direct handle GDPR and CCPA?
Our privacy program is built around GDPR and CCPA principles: data minimization, purpose limitation, lawful basis for processing, documented consumer rights, and a defined Data Subject Access Request (DSAR) process. Requests are routed to a named privacy contact and handled within statutory windows. See our Privacy Policy for full details.
Who maintains the platform, outsourced developers or an in-house team?
Both the development and security functions are in-house. Easy Pay Direct operates a full-stack, full-time in-house development team and a dedicated cybersecurity team. Code reviews, infrastructure changes, and incident response stay inside our team rather than being routed to an outsourced ticket queue.
What does the 24/7/365 monitoring actually cover?
An Intrusion Detection Service (IDS) monitors platform traffic 24 hours a day, 7 days a week, 365 days a year. Suspicious traffic, anomalous access patterns, and known attack signatures are flagged and triaged by our in-house cybersecurity team. Alerts can be surfaced to your merchant account contact when attempts target your environment.
What fraud tools come with a Easy Pay Direct account?
Every account includes 3D Secure 2 (3DS), Address Verification Service (AVS) checks, CVV/CVV2 validation, velocity limits, device fingerprinting, and chargeback alerts. Higher-risk accounts can layer in additional fraud scoring and decline-recovery tooling. None of these require a separate contract or add-on fee.
How is Easy Pay Direct's security different from Stripe's or Square's?
Stripe, Square, and similar payment facilitators pool many merchants under a single PayFac account. Their security and compliance posture applies to the shared environment. Easy Pay Direct issues a dedicated merchant account in your business name, with PCI scope, AML/KYC, OFAC screening, and incident response managed for your account specifically, not inherited from a shared pool.
Can I see Easy Pay Direct's RoC, SAQ, or security documentation?
Yes, under NDA. We provide our current Report on Compliance (RoC) or applicable Self-Assessment Questionnaire (SAQ), AML/KYC program summary, privacy policy, and security overview to qualified prospects and partners. Request access through a Certified Payment Specialist and we will share documentation under a mutual NDA.