We are direct about what we hold today and what is on the roadmap. Fidacy is not currently SOC 2 or ISO 27001 certified. Those are planned.
On our roadmap; not yet certified. Target date: contact us. No interim seal is implied.
On our roadmap; not yet certified. Target date: contact us.
No certifications claimed. Until an audit completes and a report is issued, Fidacy makes no SOC 2 or ISO 27001 representation. The security architecture described under Security stands on its own and is independent of certification status. For the current state of any certification effort, contact sales@fidacy.com.
What is battle-ready and what is not, in our own words. The money path is implemented and test-gated; the newest surfaces say so. Diligence teams should not have to reverse-engineer this.
{{ row.backs }}
Fidacy does not expand your PCI DSS scope. The engine never touches card numbers. The AP2 payment_instrument schema it receives carries only an id, a type, and a description — no PAN, no track data, no credential. Fidacy decides on signed mandates and risk_data, never on a primary account number, so adding Fidacy does not bring cardholder data into a new system.
Separately from certifications, Fidacy is built to provide evidence for the frameworks below. These are alignment and positioning claims, detailed in Compliance & Regulatory.
Corporate entity. Fidacy is operated by ZEEPCODE GROUP LLC, a Florida limited liability company. Master agreement, DPA, and any contractual SLA are available on request.