Marseille UPG runs payment-grade infrastructure on which our customers’ revenue depends. Our security programme is engineered, audited and monitored continuously — not a static document.
Mutually authenticated, segmented services. Every internal call is signed, audited and rate-limited.
TLS 1.3 in transit, AES-256 at rest, FIPS-validated HSM-backed key custody for signing material.
PAN data is tokenised or vaulted; the platform stores no cardholder data outside scope.
Hardware-key SSO and MFA for all admin paths. Per-tenant RBAC and ABAC for customer surfaces.
24/7 SOC, behavioural detection, signed audit logs and immutable forensic retention.
Quarterly external penetration tests and continuous internal red-team exercises.
The platform runs across hardened multi-tenant service meshes in three independent regions (EU, US, APAC). Each region is self-sufficient: a regional outage does not propagate to others. All inter-service traffic is mutually authenticated using mTLS and signed at the application layer.
Our incident response programme is documented, rehearsed quarterly, and integrated with customer notification channels. Severity 1 incidents are paged to executive leadership within 15 minutes and customers are notified per contractual commitments.
Every sub-processor is reviewed for security, privacy and resilience before onboarding, and continuously thereafter. Material vendors are tier-classified, contractually bound to flow-down requirements, and published in the DPA.