Trust
Security Info
How we protect merchants, cardholders, and their data across the MiCamp product line.
Compliance
Payment products are built and operated to PCI DSS requirements. Compliance documentation for each product is published in its Documents section.
Data protection
Data is encrypted in transit with TLS and at rest. Cardholder data is tokenized and never stored in plain text.
Access control
Production access follows least privilege with role-based access control, and administrative access requires multi-factor authentication.
Monitoring & response
Systems are continuously monitored, and incidents are tracked publicly on the Nexus status page.
Responsible disclosure
If you believe you have found a vulnerability in any MiCamp product, report it through the bug bounty program rather than public channels.