Skip to content
Ready to get started, Let's Go! Talk to Sales

Built end to end.
Operated as ONE.

QorCommerce is the payment platform QorPay built to run the full payment lifecycle, with the control, resilience, and visibility enterprises expect. Underwriting, boarding, intelligent routing, processing, clearing and settlement, and in-line risk all operate on one integrated platform.

The difference is ownership. Every layer is ours, every capability is connected, and every outcome makes the platform smarter. Settlement and dispute data feed directly back into Intelligent Routing, helping improve decisioning, performance, and reliability over time.

When money moves through QorCommerce, it moves on rails we own and operate: one platform, one API, no upstream handoffs. Enterprise-grade scale and control you can verify in the docs, not take on faith.

1. Underwriting Automated Underwriting · KYC / KYB · credit policy 2. Boarding MID issuance · embedded onboarding 3. Intelligent Routing the transaction prepared before it moves · staged delivery 4. Tokenization card + ACH vault · PCI scope reduction 5. Processing CP · CNP · ACH on one set of REST APIs 6. Clearing & Settlement clearing records · deposits reconciled to the penny 7. Risk & Compliance sets the signals · Network Compliance Monitoring Circuit Breaker MID / BIN health (veto) Approval Performance Least-cost network L3 / CEDP 3DS step-up token vs PAN settlement + dispute outcomes feed Intelligent Routing, the whole loop Intelligence spans the stack: MID/BIN · ARC 1 transaction key: auth · settlement · dispute, recorded once, learned from everywhere

What happens at Underwriting?

Automated Underwriting is the QorCommerce boarding engine: KYC/KYB checks, business verification, match-list screening, and risk scoring run in one flow under QorPay's own credit policy. Because the policy is ours, an application that would sit in a reseller's queue waiting on an upstream processor gets a decision from the people who wrote the rules. Clean applications flow straight through to MID issuance; edge cases route to a human review queue instead of an automatic decline. That is why merchants mainstream processors turn away can get a real review here: the engine scores the business, not just the MCC.

Platforms can embed the same flow, so their merchants board inside the platform's own UI. See Automated Underwriting for the policy details.

How does boarding work?

Boarding is the step that turns an approved application into a live merchant: MID issuance, pricing assignment, and placement in the portfolio hierarchy happen on QorCommerce the moment underwriting clears. There is no file handoff to a separate processor's boarding team, because underwriting and boarding are two stages of the same system. A merchant approved in the morning can key its first transaction the same day.

For multi-tenant operators, boarding lands merchants into Channels, the portfolio layer, with per-level pricing and access control already applied. Platform integrations are covered in the building QorCommerce solutions docs.

How is a transaction routed?

Qompliance
Home / Network Compliance Monitoring / MID/BIN Intelligence
Routing · SHADOW Refresh: 15 min ▾
Account routing detail
MER- 1042 ⌕ Inspect
MER-1042 · Alpine Outfitters
Candidate MIDs by traffic type — Health vetoes below the floor (50), Performance ranks the survivors. The ✓ MID is the one routing would select.
cnp · 3 MIDs
visa Route healthier candidate above floor
MIDHealthPerfStatus
✓ 887728214 88 91 chosen
887728202 41 88 vetoed
887728219 76 64 healthy
mastercard Stay current MID ranks best · 82 / 74
Single-MID escalation ladder
0 · Monitorabove floor — Watch alert, no action
1 · Protectreversible remediation (tighten / throttle / 3DS)
2 · Alertfan-out: ops · sponsor · merchant — human decision
3 · Stoplast resort — human-authorized only
Routing configuration
💾 Save config Ladder is kept ordered (remediate ≥ alert ≥ stop). Every value is a setting — takes effect on the next run, no deploy.
The Qompliance Console · Account Routing

Intelligent Routing is the layer that prepares a transaction before it moves, because by the time an authorization leaves the building, most of its fate is already decided. Which MID carries it, checked against MID/BIN health so a merchant account drifting toward a brand program never takes the traffic (health is a veto, not a suggestion). Which of the safe options approves best for this card, brand, and merchant category, scored continuously by the approval-performance ledger. Which network and cost path. Whether a stored token or the PAN is presented. Whether Level 3 / CEDP data rides along so the transaction qualifies for better interchange instead of silently downgrading. Whether 3-D Secure steps up. Whether a retry is even worth sending: doomed retries get killed in-line rather than burning the approval ratio.

Dozens of parameters, set in milliseconds, informed by the closed loop of authorization, settlement, and dispute outcomes on one transaction key. The layer is in staged delivery: the in-line kill controls run today as part of Circuit Breaker, with health scoring and approval-performance routing landing behind it.

What does tokenization cover?

Tokenization is the vault layer: card numbers and bank account details are swapped for tokens at the edge, so raw PANs never sit in your systems. QorCommerce vaults both card tokens and ACH tokens on the same API, and the capture surfaces (hosted checkout, Secure Embedded Forms, and qor-charge.js) are built so card data goes straight from the customer's browser to our PCI DSS Level 1 environment.

The vault is operational, not just secure: tokens are searchable by customer name, phone, email, or last four at portfolio scale, and every token carries its own transaction history, so "what has this card done with us?" is one lookup. Card and ACH tokens live in the same vault, which is what lets a saved credential move between one-time checkout and Recurring without re-collection.

Two details matter beyond the vault itself. ACH is tokenized too: bank account numbers vault the same way card numbers do, so recurring debits and larger invoice payments run on tokens, not stored account numbers. And a level of QorCommerce tokenization is portable across processors, so a credential tokenized with us is not a credential held hostage by us.

The practical effect is scope reduction: with embedded forms or hosted checkout, most integrations qualify for the shortest self-assessment questionnaires instead of a full audit. The PCI DSS compliance guide maps each integration style to its scope.

How does processing work?

Processing is the authorization layer: card-present, card-not-present, ACH, APMs, and Crypto/Stablecoin on one set of APIs, JSON in and out, idempotency built in. Card-not-present traffic runs through the payments API and the checkout surfaces above.

The lifecycle is complete, not just the sale: authorize and capture together or separately, partial captures, voids before settlement, full or partial refunds after it, and recurring charges against vaulted tokens. Response behavior is documented down to the code (approvals, declines, AVS and CVV results), so integrations are built against published tables instead of trial and error.

PROCESSING · ONE AUTHORIZATION PATH Card-present Card-not-present ACH APMs Crypto / Stablecoin { } authorize one set of APIs JSON in and out · idempotency built in the networks no gateway hop · no switch however a transaction arrives, it rides the same rails same vault · same in-line risk controls · same ledger
Five ways in, one path to the networks

In person, card-present acceptance runs through QorConnect for countertop and terminal deployments and Qor@theEdge for edge devices, and the hardware story is deliberately open. Alongside QorConnect, the platform supports a wide range of semi-integrated terminal solutions, where the device handles the card and QorCommerce handles the transaction, and OEMs certify their own equipment against the platform through Qor QAC. The certified device catalog widens on the OEMs' schedule, not a single vendor's roadmap.

However a transaction arrives, it rides the same rails: tokenized against the same vault, screened by the same in-line risk controls, settled on the same ledger. A merchant running a counter and a website reconciles one batch, not two vendors, and a platform that adds in-person acceptance later integrates nothing twice.

Because QorPay is the processor, an authorization does not hop through a gateway, then a reseller, then someone else's switch. It hits our stack and goes to the networks.

How does clearing and settlement work?

Settlement is the money-movement layer: captured transactions batch, clear through the networks, and fund merchant deposits on infrastructure QorPay operates under its sponsor banks. Every authorization, capture, fee, and deposit is reconciled on our own ledger, which is why Reporting can trace a deposit back to its batch and each batch back to its transactions: the data is first-party, not a feed from an upstream processor.

When a settlement question comes in, the team that runs the ledger answers it. There is no vendor to forward it to.

How is risk handled?

Qompliance
Home / Network Compliance Monitoring / Circuit Breakers
SHADOW — logging only
Hard-decline circuit breakers
Match repeated attempts of the same charge on a known-terminal decline and auto-declined. Matched on card identity + merchant + amount — never on order ID.
Export config + Add code
Circuit-broken (24h)⃠
212
attempts stopped
Merchants affected⌂
9
of 214 active merchants
Codes on allowlist≡
14 / 22
circuit-break · allow-always
Avg. match latency◷
3.2 ms
lookup at seam
Global defaultsPer-merchant overrides (3)Soft declines (6)Shadow logActive blocksAudit logToken kill
CodeMeaningMatch keyActionStrikeLast 24h
07 Pick up card (fraud) tokenmerchantamount Circuit break First-strike 38 stopped · 6 merchants
43 Confiscate card (reported stolen) tokenmerchantamount Circuit break First-strike 21 stopped · 4 merchants
63 Security violation tokenmerchant≥ amount Circuit break N=2 tolerant 9 stopped · 3 merchants
51 Insufficient funds tokenmerchant Allow always — not matched
The Qompliance Console · Circuit Breakers

Risk & Compliance is the layer that sets the signals: exposure limits, velocity thresholds, dispute-ratio ceilings, and card-brand rules, tracked continuously by Network Compliance Monitoring. Enforcement happens where the transaction is: Circuit Breaker, operating in the Intelligent Routing layer, acts on those signals in real time, halting anomalous flow and doomed retries before they move. Signals set here, enforced in-line there: that separation is what keeps detection continuous and enforcement instant.

Around those modules sit the standard controls: AVS and CVV checks, 3-D Secure, and the fraud prevention toolkit. Disputes follow a documented flow: see how disputes work. Because risk and processing are the same platform, a Circuit Breaker halt is a platform action, not a phone call to a third party.

Where is the intelligence?

Spanning the layers, not bolted on top. Owning the stack means QorCommerce records authorization, settlement, and dispute outcome against the same transaction key: the closed data loop that AI tools riding on someone else's processor never see. Two systems are being built directly on that loop.

MID/BIN Intelligence works the transaction path: its first delivered piece, Circuit Breaker, is deployed in the in-line auth stream, with health scoring and approval-performance routing in staged delivery behind it.

◔ Operations Team
20 team members on duty today. Live
Filter Export + Hire new Agent
On duty◈
20
across 8 departments
In queues≣
147
+12 last hr
Holds (24h)◐
43
all reversible
Escalated to humans✓
7
0 boundary
Team roster
Drift = Warden's anomaly signal on outputs · Status = operational health
View all activity →
NameDriftScheduleQueueStatusLast activity
WT Watchtower stable stream 23 healthy 2s ago
SA Sentinel-AML stable stream 4 healthy 11s ago
SG Signal watch stream + agg — healthy 3s ago
GK Gatekeeper stable event (pool 4/8) 18 healthy 45s ago
NO Notary stable event 9 healthy 1m ago
LE Ledger stable event-on-sched 2 awaiting file 2h ago
BW Bellwether — cron (daily) — scheduled 04:00 23h ago
ARC · Operations Team · preview

The Agentic Resource Center (ARC) works the operator side: regulated payments work, run through AI, with every money-moving decision still in human hands. ARC is a governed team of specialized AI agents working the highest-stakes corners of the payments lifecycle (merchant underwriting, transaction risk and financial-crime monitoring, settlement, and disputes) with dedicated oversight agents watching the rest, under one rule: the deeper into the money flow, the less an agent may act. Machines draft and recommend; people own and sign every irreversible decision; and every step lands in an audit trail an examiner can walk field-by-field, same day. The stack is deliberately model-agnostic: frontier models from multiple vendors routed through a single in-house gate that logs every request. ARC's first resident, Ask Qora (a concierge that answers account questions with live account data), is in beta now.

This is the part competitors can't copy by buying the same models: everyone has the models. The moat in AI isn't the models; it's the audited pathway that makes them approvable, and the operating history that compounds behind it. Provable beats promised.

Frequently Asked Questions (FAQs)

Is QorCommerce built on another processor?

QorCommerce is the platform QorPay owns and operates, and it performs all merchant servicing itself: underwriting, boarding, risk, reporting, and settlement. Two rails carry the volume. The PayFac program, sponsored by Pathward, N.A., clears through Fiserv at the network seam. QAC, QorCommerce's own processing rail, runs under nobody but QorPay and its sponsor banks. On either rail, the platform your integration touches is ours end to end.

What is Circuit Breaker?

Circuit Breaker is the QorCommerce risk module deployed in-line with authorization: it watches transaction flow in real time and catches anomalous activity (velocity spikes, exposure breaches, out-of-pattern amounts) as it happens, with enforcement rolling out per portfolio. Because it runs in the auth stream, it works on live traffic, not yesterday’s batch.

What is Network Compliance Monitoring?

Network Compliance Monitoring is the QorCommerce module that tracks card-brand rules and registrations continuously. It watches for the things that get merchants fined or terminated (registration lapses, prohibited activity, brand-program requirements) and flags them before the networks do.

Can I use only part of the platform?

Yes. The layers are one platform but separate modules: platforms can embed boarding without processing, merchants can process without touching the portfolio tooling, and ISOs can run portfolios on top of the whole stack. Start with the layer you need and add the rest when it earns its way in.

Is QorCommerce an AI-native platform?

It is becoming one, from the data up. The platform records authorization, settlement, and dispute outcome on one transaction key, and its intelligence systems, MID/BIN Intelligence in the auth stream and the Agentic Resource Center (ARC) on the operator side, are built directly on that loop, under one rule: the deeper into the money flow, the less an agent may act. Circuit Breaker is deployed; Ask Qora is in beta; the rest lands in stages rather than as a press release. The moat isn't the models; it's the audited pathway that makes them approvable.

How do I integrate with QorCommerce?

Through the REST APIs: JSON in and out, two header keys for auth, idempotent POSTs. The sandbox is public and the test cards are documented, so a first test transaction takes minutes. Start at the developer hub or go straight to the docs.

Want to see the stack on your traffic?

Tell us your volume, your verticals, and your integration surface. We'll walk the exact path a transaction takes through QorCommerce, underwriting to deposit.