Skip to content
Ready to get started, Let's Go! Talk to Sales

Compliance

Registrations and certifications are the paperwork that lets us exist. Here is QorPay's, stated plainly: who sponsors us, what we're audited against, and where to get the documents your risk team will ask for.

Registered PayFac Pathward, N.A. Registered ISO Synovus Bank Registered ISO Chesapeake Bank PCI DSS Level 1 Annual QSA on-site audit HIPAA Compliant platform American Express OptBlue program Audited · Registered · Sponsored The paperwork that lets us exist, held by us

Bank Registrations

These are QorPay's registrations, verbatim:

  • QorPay Inc. is a registered Payment Facilitator of Pathward, N.A., Sioux Falls, SD
  • Registered ISO of Synovus Bank, Columbus, GA
  • Registered ISO of Chesapeake Bank, Kilmarnock, VA

The PayFac registration with Pathward is what lets QorPay board sub-merchants under its own program. The ISO registrations with Synovus and Chesapeake support direct merchant acquiring. American Express acceptance comes through the OptBlue program, so merchants get Amex on the same statement and settlement as Visa and Mastercard.

PCI DSS Level 1

QorPay is a PCI DSS Level 1 service provider. Level 1 is the tier the card networks require of providers processing over 6 million transactions a year, and it is validated differently from every other tier: a Qualified Security Assessor (QSA), an independent auditor certified by the PCI Security Standards Council, conducts an annual on-site assessment of our systems, controls, and evidence, then issues a Report on Compliance.

Contrast that with a Self-Assessment Questionnaire (SAQ), where a company checks its own boxes and signs its own attestation. An SAQ is legitimate for small merchants; it is not the same thing as an audit. When a provider says "PCI compliant," ask which tier and who validated it.

Our current Attestation of Compliance is available for vendor reviews: Download the PCI AoC (PDF).

HIPAA

The QorCommerce platform is HIPAA compliant. This matters for healthcare merchants because payment records can constitute protected health information (PHI): a charge from a specialty clinic, an invoice line naming a procedure, a patient's stored payment credential. PCI DSS covers the card data; HIPAA covers the health context around it. QorCommerce is operated to satisfy both, so practices, billing companies, and health-tech platforms can process payments without building a separate PHI handling story for their processor.

Getting Documents

Vendor reviews usually need the same short list: the PCI Attestation of Compliance, the bank registration language above, and answers to a security questionnaire. Contact us and we'll send them. For ongoing card-brand rule tracking, see how Network Compliance Monitoring works on the platform.

Frequently Asked Questions (FAQs)

What is the difference between PCI Level 1 and the other levels?

Level 1 is the strictest tier of PCI DSS, required of providers handling over 6 million transactions a year. It requires an annual on-site audit by a Qualified Security Assessor. Lower levels can self-certify with a questionnaire; Level 1 cannot.

Does using QorPay reduce my own PCI scope?

Usually, yes. If card data is captured through hosted checkout or embedded forms, it never transits your servers, which typically puts you at the SAQ A end of the compliance spectrum. Your exact scope depends on your integration and should be confirmed with your assessor.

Can QorPay sign a Business Associate Agreement (BAA)?

The QorCommerce platform is HIPAA compliant, which matters when payment records carry protected health information. Contact us to discuss BAA terms for your specific use case. (TODO: confirm standard BAA process.)

Why do the bank registrations matter?

Card network access runs through sponsor banks. A processor without registrations is reselling someone else’s. QorPay holds its own: Payment Facilitator of Pathward, N.A., and ISO of Synovus Bank and Chesapeake Bank, with American Express acceptance through the OptBlue program.

Running a vendor review?

Ask for the AoC, the questionnaire answers, and a call with someone who can explain the controls, not a PDF dump.