Payment data certifications: PCI DSS, SOC2, ISO27001
SDK.finance’s transactional engine is designed to allow financial institutions and businesses to meet the regulatory requirements of different regions.
This flexibility ensures that solutions built on the SDK.finance Platform can comply with local regulations, though it remains the responsibility of the customer to achieve and maintain regulatory compliance.
PCI DSS compliance
SDK.finance is a PCI DSS Level 1 Service Provider assessed against PCI DSS v4.0.1 by 7Security GmbH. The assessment covers applicable controls for software development and information security governance, including vulnerability management, change management and incident response.
The latest published certificate records validation on 10 December 2025 and a one-year validity period. Customers remain responsible for meeting PCI DSS requirements applicable to their own payment environments.
SOC 2 compliance
SOC 2 (Service Organization Control Type 2) is a cybersecurity standard focused on safeguarding customer data. Since SDK.finance does not store or process user data—this responsibility rests with the customer—SOC 2 compliance may not directly apply to the Platform.
That said, SDK.finance is committed to security best practices and is working towards SOC 2 certification for our code storage and development processes, ensuring that our internal controls meet the highest security standards.
ISO/IEC 27001:2022 certification
SDK.finance, operated by TechFin UAB, holds ISO/IEC 27001:2022 certification issued by DNV Business Assurance. The certification covers information security management within the software development scope specified in the certificate.
This provides customers with independently assessed information security practices to support their vendor evaluation and compliance efforts. The certificate lists a validity period from 1 August 2025 to 31 July 2028.
GDPR readiness
SDK.finance’s GDPR Compliance Assurance Statement describes the technical and organisational measures intended to support customers’ data protection obligations when building financial products on the Platform.
GDPR compliance depends on how each solution is configured and operated, including its data processing purposes, retention policies and procedures for handling individuals’ rights. Customers remain responsible for aligning their implementation with applicable legal and operational requirements.