Now self-serveAccess PayOS data to make better payment decisions, no sales call needed.Start building →
Integrations · PCI

Offer card services without PCI compliance.

Accept card details on your own branded endpoint. Card data terminates at the PayOS edge, and only tokens-grade data reaches your platform.

Where card data stops.

Four steps. The card reaches PayOS, never your servers.

1
You
Expose your endpoint
On your own subdomain.
2
Your customer
Submits a card
Card number and security code.
3
PayOS
Runs your checks
In memory, one round trip, then discarded.
PCI DSS L1 SOC 2
4
You
Receive the results
PAR, BIN, last four, verification results.
Steps two and three sit entirely with PayOS. Your platform stays out of PCI scope.

Division of responsibility.

You own the product. PayOS owns the card and the compliance around it.

You
Your endpoint, your domain
Your keys, your clients
Your API contract
No card data on your servers
PayOS
Certificate for your subdomain
Card intake and your checks
Deleted when the request ends
PCI DSS Level 1 and SOC 2

The full card suite, outside PCI scope.

Every card service is available through the proxy, and none of it places a card number on your servers.

VISA
4242 •••• 4242
A. RIVERA 09/28
Arrives at your endpoint
PayOS
Everything we know about it
Issuer & network Funding type Country & currency PAR Card art Prepaid detail Rewards program Verification results 3-D Secure result Decline guidance
Everything returns as tokens-grade data. Your PCI scope is unchanged.

What you set up.

No vault to build and no card storage to certify.

1
Two DNS records
One to route your subdomain, one for its certificate.
2
One locked endpoint
Accepts our traffic only, via allowlist and mutual TLS.
3
Your existing keys
Clients authenticate with the keys you already issue.

A verification product under your own brand.

Your clients post a card to your verification endpoint. PayOS runs the checks in one round trip and returns the outcome plus a durable card reference. A complete verification product, with no card number entering your infrastructure.

Nothing is vaulted
Card data exists in memory at the edge for a single request, then is discarded with it. It is never vaulted, logged or persisted.
A hard scope boundary
No card data crosses into your platform. Everything past the edge is tokens-grade: PAR, BIN, last four and operation results.
Certified infrastructure
The PayOS edge and analysis core operate under PCI DSS Level 1 and SOC 2. The certified environment is ours, not yours.

Launch card services without the compliance overhead.

Choose your hostname, we configure your operations, and you verify end to end in sandbox.