---
title: Trust and security | Ordr
description: Data custody, certifications, reference architecture and dispute exposure, with the six questions every operator should ask a payments vendor.
---

[![Ordr](https://ordr.io/hubfs/New%20Ordr%20Pictures/brand-ordr-wordmark.png)Commerce Intelligence](https://ordr.io/?hsLang=io)

Platform

Solutions

Research

Customers

[Schedule a demo](https://ordr.io/trust#demo)

[![Ordr Pay](https://ordr.io/hubfs/New%20Ordr%20Pictures/brand-ordr-pay.svg)](https://ordr.io/pay?hsLang=io)[**Merchant processing**Interchange optimised, gateway agnostic, no headline rate games](https://ordr.io/pay#processing)[**Virtual payments**Text to pay, email links, and a PCI compliant agent portal](https://ordr.io/pay#virtual)[**Agentic payments**Machine initiated purchase, on rails that already shipped](https://ordr.io/pay#agentic)[**Alternative payments**Wallets, PIN debit, pay by bank, and stablecoin settlement](https://ordr.io/pay#alternative)

[![Ordr Insights](https://ordr.io/hubfs/New%20Ordr%20Pictures/brand-ordr-insights.svg)](https://ordr.io/insight?hsLang=io)[**Fan IQ**One fan profile across ticketing, concessions, retail, and premium](https://ordr.io/insight#fan-iq)[**Partner IQ**Attribution your partners can renew against, not impressions](https://ordr.io/insight#partner-iq)[**Transact IQ**Every rate, every downgrade, every overcharge, in one view](https://ordr.io/insight#transact-iq)

Live**Fan IQ is live with Ticketmaster**

Ticketing, entry, concessions, retail, and partner activation resolved to one fan.

[Read the case study →](https://ordr.io/customers/ticketmaster?hsLang=io)

#### By role

[**Finance**Rate visibility, dispute exposure, and a close that lands the same night](https://ordr.io/solutions/finance?hsLang=io)[**Partnerships**Prove what an activation delivered before the renewal conversation](https://ordr.io/solutions/partnerships?hsLang=io)[**Ticketing**Join the seat to the sale without leaving your ticketing platform](https://ordr.io/solutions/ticketing?hsLang=io)[**Operations**One system across gate, counter, retail, and premium](https://ordr.io/solutions/operations?hsLang=io)[**Technology**One integration layer instead of nine vendor relationships](https://ordr.io/solutions/technology?hsLang=io)

#### By moment

[Gate and entry](https://ordr.io/solutions/moments#gate) [Concessions and retail](https://ordr.io/solutions/moments#concessions) [Premium and suites](https://ordr.io/solutions/moments#premium) [Partner activation](https://ordr.io/solutions/moments#partner)

#### Field reports

[**The 2026 Venue Payments Report**What changed at the counter this season, and what it cost](https://ordr.io/research#report)[**Custody, compliance, and the cost of a fragmented stack**Data ownership, card security standards, and dispute economics](https://ordr.io/research/field-report-01?hsLang=io)[**All research**Everything Ordr has published, with sources](https://ordr.io/research?hsLang=io)

#### Company

[**News**Announcements, partnerships, and coverage](https://ordr.io/news?hsLang=io)[**About Ordr**Who we are and why we built this](https://ordr.io/about?hsLang=io)

Free**The 2026 Venue Payments Report**

Built from network transaction data and interviews with finance leads across sports and live entertainment.

[Get the report →](https://ordr.io/research#report)

#### Proof

[**Case studies**Named clubs, measured results, stated method](https://ordr.io/customers?hsLang=io)[**Vegas Golden Knights**55 bps off interchange and $82.5k in chargebacks recovered](https://ordr.io/customers/golden-knights?hsLang=io)[**Pittsburgh Penguins**A dozen vendors consolidated, 53% off processing in 60 days](https://ordr.io/customers/penguins?hsLang=io)[**Ticketmaster**The integration that joins the ticket to the counter](https://ordr.io/customers/ticketmaster?hsLang=io)

#### Trust

[**Trust and security**Certifications, architecture, and who owns the fan record](https://ordr.io/trust?hsLang=io)[**How we handle data**What we hold, why we hold it, and for how long](https://ordr.io/trust#custody)

Trusted by**The clubs, the resorts, and the rails**

NHL, AHL, CFL and WNBA clubs, MLS, a Las Vegas resort, and the platforms underneath them.

[See the roster →](https://ordr.io/customers?hsLang=io)

# *Your fans. Your data.**Our *rails*.*

The questions an enterprise buyer asks before the demo, answered before the demo. Take them into every payments conversation you have this year, including the one with us.

[Request the technical pack →](https://ordr.io/trust#demo)[Read field report 01](https://ordr.io/research/field-report-01?hsLang=io)

Payment topologyTwo paths

##### Funds path

CaptureGateway orchestrationAcquirer, operator MIDsOperator bank accounts

##### Data path

CaptureMatching engineOne resolved profileOperator CRM, loyalty, sponsorship

##### Never shared between them

SettlementMerchant of recordBank credentials

**PCI DSS**v4.0.1 is the active standard

**SOC 1 and SOC 2**Security governance

**P2PE capable**Tokenised at capture

**150 bps**Visa merchant excessive threshold

## The club owns the fan record.

This is the question most payment vendors never answer in writing, and the one an operator should ask first.

01

### Who is accountable

The club or operator is the accountable organisation. Ordr is a processor working to the club's instructions, for the club's purposes, and for no others. Any arrangement that cannot be described in those terms should be read closely.

- **Enriched records return to systems you own.** Your CRM, your ticketing platform, your BI stack, exportable in full at any time.
- **No resale.** Ordr does not sell client data to anyone.
- **No cross client modelling.** Your fans do not train anything for another club.
- **No marketing to your fans.** Not by us, not by a partner of ours.
- **No retention after termination** beyond the window stated in your agreement.

Custody chainContractual

##### The fan

Consents once, to the club's terms

##### The club

Accountable organisationSets the purposeOwns the record

##### Ordr

Processor onlyPurpose limited by contractComparable protection required

![A fan tapping to pay at a reader](https://ordr.io/hubfs/New%20Ordr%20Pictures/img-fan-tapping-a-phone-at-a-stadium-reader.jpg)

## Tokenised at capture.

The card credential is tokenised at the point of authorisation. Primary account numbers do not enter club systems, which is what takes those systems out of PCI scope rather than merely encrypting what is already there.

[See the platform](https://ordr.io/pay?hsLang=io)

## Encrypted in use, not just at rest.

Ordr’s payment data runs on Cy4Secure, Cy4data’s persistent encryption platform. Most stacks encrypt data at rest and in transit, then decrypt it to work on it. That decryption window is the gap Cy4Secure closes: the data stays encrypted while it is queried, processed and shared, so a stolen credential or a copied database yields cipher text rather than a record.

01**At rest, in motion and in use**

AES-256 applied at the element level, down to a single field or record. Databases operate natively on the encrypted data, so nothing is decrypted to run a query and there is no performance cost to carrying it.

02**Keys and data live apart**

Encryption keys are held separately from the data, with no connection between key locations, data stores and users. Possession of a password is not possession of the keys, which is what takes an insider or a supply chain compromise off the table.

03**Every key request is watched**

Keys are issued only to authorised users and applications. Access is monitored in real time, abnormal patterns are stopped by machine learning detection and multi factor verification is forced, so credential dumping, account takeover and man in the middle attempts fail at the key rather than at the door.

Persistent encryption is how Ordr meets PCI DSS requirements 3 and 4, protecting stored cardholder data and encrypting it in transmission, and it supports the same obligations under GDPR and CCPA. Platform details from the Cy4data security and compliance certification issued for Ordr, reviewed annually. The requirement by requirement mapping is in the technical pack.

## Reference architecture.

The most useful thing a payments partner can publish is a topology, because it shows without adjectives which path the money takes, which path the data takes, and whether they are the same path.

**The funds path and the data path are separate.**

Settlement moves from the acquirer into your accounts under your merchant identifiers. The intelligence layer never sits in the funds path.

**Which means it is removable.**

Dropping the analytics would not force a payments re-tender. Apply that test to any vendor diagram, ours included: if removing the data product breaks settlement, the paths were never separate and your switching cost is higher than the contract suggests.

**Gateway agnostic by design.**

Certified with FreedomPay and Moneris, with native connectivity to Micros Simphony and to Ticketmaster through Archtics Transaction Services.

**Role based access, event and device level.**

Reporting, reconciliation and dispute evidence are scoped to the people who need them, down to the individual fixture and the individual terminal.

[Read the full architecture →](https://ordr.io/research/field-report-01?hsLang=io)

## Named, not implied.

Ordr holds PCI DSS, SOC 1 and SOC 2, and is P2PE capable. The technical pack names the version, the assessment type, the observation window and the criteria in scope, because a certification without those four things is a word rather than a claim.

01**PCI DSS v4.0.1 is the standard that applies**

Version 3.2.1 was retired on 31 March 2024, and the 51 future dated requirements in v4.0 became mandatory on 31 March 2025. Any assessment conducted in 2026 is conducted against v4.0.1.

02**SOC 1 and SOC 2 are different reports for different questions**

SOC 1 addresses controls relevant to financial reporting. SOC 2 addresses the trust services criteria. Security is mandatory in every SOC 2. The others are selected against the commitments the provider has actually made.

03**P2PE capable is not the same claim as a validated P2PE solution**

We say capable because that is the accurate word for the hardware and the architecture. Vendors who blur those two claims are worth a follow up question.

PCI DSS version status from the [PCI Security Standards Council](https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1).

## The math changed in April.

On 1 April 2026 the Visa merchant excessive threshold under the Acquirer Monitoring Program dropped from 220 basis points to 150. An operator that was comfortably compliant under the old ceiling can be in breach today without changing a single operational practice.

150 bps

The merchant excessive threshold from 1 April 2026, down from 220. Acquirer level thresholds sit tighter still, at 50 basis points standard and 70 excessive.

Visa, 2026[Open the fact sheet →](https://corporate.visa.com/content/dam/VCOM/corporate/visa-perspectives/security-and-trust/documents/visa-acquirer-monitoring-program-fact-sheet-2025.pdf)

By count

The ratio is measured by transaction count rather than value, so a high volume game night carries proportionally more exposure than the same revenue spread across fewer, larger transactions.

Why arenas are exposed[See Transact IQ →](https://ordr.io/insight#transact-iq)

$82 + $46

Internal cost plus third party fees on a single chargeback, before the value of the goods. The Vegas Golden Knights recovered $82,500 of it.

Mastercard, June 2026[Open the source →](https://www.mastercard.com/global/en/news-and-trends/Insights/2025/what-s-the-true-cost-of-a-chargeback-in-2025.html)

There is a trap in the obvious response. Tightening fraud rules to decline more transactions shrinks the denominator without shrinking the numerator, which can push the ratio further out of compliance. Approving more legitimate transactions while reducing genuine disputes requires transaction level evidence, not a stricter rule.

## One mesh. Every transaction in it.

A bank note is engraved rather than printed because the pattern is the proof. The same idea runs through this platform: one continuous surface where every transaction, every fan and every partner activation sits in the same weave rather than in nine separate documents.

[See Ordr Insights →](https://ordr.io/insight?hsLang=io)

## Six questions, and the non answers.

Take these into every payments conversation you have this year. The second half of each card is what a vendor says when the real answer is inconvenient.

01**Which PCI DSS version were you assessed against, and when?**

A usable answer names the version, the assessment date, the assessor and the report type. "We are PCI aligned" is not a standard and not an answer.

02**SOC 2 Type I or Type II, and over what period?**

Type I is an opinion on whether controls are suitably designed at a point in time. Type II tests whether they operated over an observation window. A usable answer names the type, the window and the criteria in scope.

03**Where does cardholder data live, and who is in PCI scope?**

A usable answer is that card credentials are tokenised at capture, no primary account numbers enter club systems, and the scope reduction is documented. "Everything is encrypted" is not.

04**Who is merchant of record, and where do funds settle?**

A usable answer is that the operator is merchant of record and funds settle directly into the operator's own accounts. "We handle settlement for you" is a different arrangement.

05**On termination, what do we get back and what do you keep?**

A usable answer is a full export in a documented format and a stated deletion window. Silence, or "we would work with you on that", is the answer to be worried about.

06**Where is the data resident?**

A usable answer names the region, names the provider and puts both in the contract. "Secure cloud infrastructure" names nothing.

[Request the technical pack →](https://ordr.io/trust#demo)[Read field report 01](https://ordr.io/research/field-report-01?hsLang=io)

## Ask the hard one.

Send the question your security team would ask if they were on the call. If the answer is not flattering to us we will still give it to you in writing.

> Switching to Ordr was one of the smartest and easiest decisions we've made. By moving our payments under Ordr, we gained visibility into hidden costs and started unlocking valuable, revenue-driving data.

**Mike Dillon**Chief Financial Officer, Pittsburgh Penguins

First name

Last name

Work email

Organisation

Phone optional

How can we help?Choose oneLower what we pay in card feesTake payments away from a terminalGet usable data out of our transactionsProve what our partners actually deliveredReplace several vendors with oneSomething else, or not sure yet

Request the technical pack

We use this to route you to the right person. No sequence, no drip.

### Thank you.

Your request is in. Someone from Ordr will reply directly, usually within one business day.

[![Ordr](https://ordr.io/hubfs/New%20Ordr%20Pictures/brand-ordr-wordmark.png)](https://ordr.io/?hsLang=io)

The commerce intelligence layer for sports and live entertainment. One ledger across ticketing, the counter, retail and premium.

#### Platform

[Ordr Pay](https://ordr.io/pay?hsLang=io)[Merchant processing](https://ordr.io/pay#processing)[Virtual payments](https://ordr.io/pay#virtual)[Agentic payments](https://ordr.io/pay#agentic)[Alternative payments](https://ordr.io/pay#alternative)[Ordr Insights](https://ordr.io/insight?hsLang=io)[Fan IQ](https://ordr.io/insight#fan-iq)[Partner IQ](https://ordr.io/insight#partner-iq)[Transact IQ](https://ordr.io/insight#transact-iq)

#### By role

[Finance](https://ordr.io/solutions/finance?hsLang=io)[Partnerships](https://ordr.io/solutions/partnerships?hsLang=io)[Ticketing](https://ordr.io/solutions/ticketing?hsLang=io)[Operations](https://ordr.io/solutions/operations?hsLang=io)[Technology](https://ordr.io/solutions/technology?hsLang=io)[By moment](https://ordr.io/solutions/moments?hsLang=io)

#### Customers

[Case studies](https://ordr.io/customers?hsLang=io)[Vegas Golden Knights](https://ordr.io/customers/golden-knights?hsLang=io)[Pittsburgh Penguins](https://ordr.io/customers/penguins?hsLang=io)[Ticketmaster](https://ordr.io/customers/ticketmaster?hsLang=io)[Trust and security](https://ordr.io/trust?hsLang=io)

#### Company

[About Ordr](https://ordr.io/about?hsLang=io)[News](https://ordr.io/news?hsLang=io)[Research](https://ordr.io/research?hsLang=io)[Venue Payments Report](https://ordr.io/research#report)[Schedule a demo](https://ordr.io/trust#demo)

© 2026 Ordr Technologies Inc. [Privacy](https://ordr.io/privacy?hsLang=io) [Terms](https://ordr.io/terms?hsLang=io) [Trust and security](https://ordr.io/trust?hsLang=io)