Compliance & PCI-DSS
Last updated: July 2026.
1. Our commitment to compliance
Cartflox places regulatory compliance at the heart of its operations. As a payment infrastructure serving several African countries, we comply with all the regulatory frameworks applicable in each of our markets.
Cartflox claims no licence as a payment institution or an electronic money institution. This page states what we do, and what we do not do.
2. PCI DSS compliance
Cartflox stores no bank card data. Card forms are provided and hosted by our providers, who are themselves PCI DSS certified.
In practice:
• Card numbers never pass through our servers, they go straight to the provider that processes them
• All communications are encrypted with TLS
• Our merchants' API keys are encrypted at rest (AES-256-GCM)
• Access to sensitive data is controlled and logged
Cartflox is not PCI DSS certified in its own name and provides no PCI DSS coverage to its merchants: the certification is held by the providers that handle card data.
3. Anti-money laundering (AML/CFT)
Cartflox applies a rigorous anti-money laundering and counter-terrorist financing (AML/CFT) policy:
• Mandatory KYC (Know Your Customer) procedures for all merchants
• Identity verification and verification of the structure of business entities
• Continuous transaction monitoring (real-time risk scoring)
• Automatic reporting of suspicious transactions to the competent authorities
• Regular AML/CFT training for our teams
• Maintenance of a register of beneficial owners
Anti money laundering checks on the payment flows themselves are carried out by the licensed aggregators that execute the payments, under their own obligations.
4. African regulatory compliance
We comply with the regulatory frameworks of the markets where we operate:
Côte d'Ivoire:
• BCEAO regulation on payment systems
• Law on cybercrime and data protection
• ARTCI regulation on digital financial services
WAEMU (UEMOA) zone:
• Directive on payment services and electronic money
• Regulation No. 15/2002/CM/UEMOA on payment systems
Other markets:
• Compliance with local regulations in every country where we are deployed
5. Data protection (GDPR & local laws)
Although we are based in Côte d'Ivoire, we apply data protection standards aligned with international best practice:
• Data minimisation
• Defined and enforced retention periods
• Right to erasure and data portability
• Data breach notification within 72 hours
• Appointed Data Protection Officer (DPO)
See our Privacy Policy for full details.
6. Audit and internal control
Our compliance programme includes:
• Quarterly internal audits
• Annual external audit by an independent firm
• Compliance committee meeting monthly
• Twice-yearly penetration tests
• Secure code reviews at every deployment
• Bug bounty programme for responsible vulnerability disclosure
Audit reports are available on request for merchants subject to specific regulatory obligations.
7. Compliance contact
For any question about our compliance programme:
Contact: https://cartflox.com/en/contact (subject: Compliance)
Phone: +225 07 03 32 46 74
Address: Abidjan, Côte d'Ivoire
Merchants who wish to obtain our PCI DSS report or other compliance documents can request them by email.