Security, Compliance and Trust at Cliq

Cliq is a U.S.-based payment technology company that has operated within the regulated payments system since 2007, under the oversight of sponsor banks and the card networks. Cliq helps merchants, ISOs, ISVs, and enterprise partners accept, move, and manage money across card processing, ACH, prepaid card programs, treasury, and embedded payments backed by independent security and compliance programs built to protect payment data.

Data Security

Cliq protects cardholder data through layered controls — encryption, tokenization, segmented access, and continuous monitoring — built on recognized security standards and validated through independent assessment.

Security is integrated into every layer of the Cliq payment platform. The standards Cliq maintains, the independent assessments it undergoes, and the validation that can be verified independently are set out below.

PCI DSS

Cliq maintains PCI DSS security controls across the systems that store, process, and transmit cardholder data, and undergoes independent validation to confirm those controls operate effectively.

SOC 2 Type II

Cliq operates within a SOC 2 Type II control environment, an independent examination of how Cliq's controls for security, availability, and confidentiality operate over a sustained period rather than at a single point in time. SOC 2 Type II reporting is available to qualified counterparties through Cliq's security review process.

Independent Validation

Cliq is listed on the Visa Global Registry of Service Providers — Visa's public registry of agents that have successfully completed PCI DSS validation and are registered with Visa. This listing is independently verifiable by confirming the entry under “Cliq, Inc” on Visa's site.

Encryption and Tokenization

CARDHOLDER DATA

  • Cardholder data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Cardholder data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Stored payment credentials tokenized — primary account numbers replaced with tokens that are useless if intercepted
  • Segmented cardholder data environment with restricted, logged access
  • Key management with scheduled rotation under dual control

Monitoring, Testing, and People

DETECTION & RESPONSE

  • Penetration testing and vulnerability management, with ASV scans as required under PCI DSS
  • 24/7 monitoring and alerting on production systems
  • Documented incident response procedures with defined notification commitments
  • Background checks, role-based access, and recurring access reviews for personnel with data access

Security Review Process

DOCUMENTATION

Subject to Cliq's security review process and applicable confidentiality requirements, qualified counterparties can request Cliq's security documentation for due diligence:

  • PCI Attestation of Compliance and SOC 2 Type II report
  • Penetration test summary and completed security questionnaires (SIG/CAIQ)
  • Request via security@cliq.com

Sponsor Bank & Network Oversight

Cliq operates inside the regulated U.S. financial system — its programs run under the oversight of sponsor banks and the card networks.

Cliq's Sponsor Bank and Network Relationships

Cliq operates within the regulated U.S. payments ecosystem through relationships with regulated financial institutions, card networks, and payment partners. Cliq's payment programs are subject to sponsor bank oversight, card network operating rules, and applicable federal and state regulatory requirements. The following disclosures apply to Cliq's programs:

  • Cliq is a registered ISO of PNC Bank, N.A.
  • Cliq is a registered ISO/MSP of North American Banking Company.
  • Stored payment credentials tokenized — primary account numbers replaced with tokens that are useless if intercepted
  • Cliq is a registered ISO/MSP of Avidia Bank.
  • Prepaid card programs are issued by Pathward, N.A., Member FDIC, pursuant to licenses from Visa U.S.A. Inc. and Mastercard International Incorporated.

Cliq works closely with sponsor banks, payment networks, processors, and compliance partners to maintain the operating standards these relationships require.

Why Businesses Trust Cliq

Trust in a payment provider is earned in the details — the controls, the oversight, and the people running both. Cliq’s focus in these areas is foundational to its business practices.

Secure Payment Processing

Security is built into every aspect of the platform, supported by industry-recognized standards, independent assessments, and ongoing compliance monitoring. Cliq maintains PCI DSS controls and operates within a SOC 2 Type II control environment to protect sensitive payment information.

Compliance at the Core

Compliance is a core component of the Cliq operating model. Cliq's payment programs are subject to ongoing oversight from sponsor banking partners, payment networks, and industry compliance requirements.

Operational Excellence & Risk Management

Successful payment programs require more than technology. Dedicated teams at Cliq support merchant onboarding, compliance management, risk monitoring, operational performance, and customer success.

Our Commitment to Customers and Partners

Trust is earned through transparency, accountability, security, and consistent performance.

Cliq works closely with merchants, banking partners, payment networks, and technology providers to deliver secure, compliant, and reliable payment solutions. Our goal is to help businesses grow confidently while maintaining high standards for operational excellence and customer service.

The Cliq Trust Center provides visibility into the governance, security controls, compliance practices, and operational processes that support our commitment to customers, partners, and the broader payments ecosystem.

Questions? Contact our security team: compliance@cliq.com