generated: '2026-08-09' method: derived source: openapi/connexpay-chargebacks-openapi.yml, openapi/connexpay-checkout-session-openapi.yml, openapi/connexpay-merchant-payor-openapi.yml, openapi/connexpay-payment-instruction-openapi.yml, openapi/connexpay-purchases-openapi.yml, openapi/connexpay-push-to-card-openapi.yml, openapi/connexpay-reporting-authentication-openapi.yml, openapi/connexpay-reporting-openapi.yml, openapi/connexpay-sales-openapi.yml, openapi/connexpay-stop-payment-service-openapi.yml, https://docs.connexpay.com/ standards: - id: openapi-3.1 conforms: true evidence: 'All ten harvested documents declare openapi: 3.1.0 (one, the Payor surface, is a Swagger 2.0 upload rendered as 3.1 by the docs platform).' - id: oauth2 conforms: false evidence: The Sales API declares an oauth2 securityScheme with an EMPTY flows object — a docs-platform placeholder, not a real OAuth 2.0 deployment. The actual mechanism is a username/password grant against a per-API token endpoint returning a bearer token; there is no authorization server, no scopes, and no /.well-known/oauth-authorization-server (probed 404 on every host). - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on all eight ConnexPay hosts probed. - id: rfc9457-problem-details conforms: false evidence: No operation in any harvested spec returns application/problem+json; errors are plain application/json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on all eight hosts probed. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; no Sunset/Deprecation header documented. - id: rfc9728-oauth-protected-resource conforms: true evidence: https://docs.connexpay.com/.well-known/oauth-protected-resource/mcp returns 200 with a valid protected-resource document. Served by the ReadMe docs platform for its MCP endpoint, not by the ConnexPay API itself. - id: asyncapi conforms: false evidence: ConnexPay operates a real event surface (CXP Eventing, 51 documented webhook event types) but publishes no AsyncAPI document. See asyncapi/connexpay-webhooks.yml. - id: emv-3-d-secure conforms: true evidence: Dedicated 3-D Secure authentication endpoints (3ds-authentication, get-3ds-status-group, 3ds2-sales) plus separate documented process flows and payload responses for US/CA and EU clients, including device fingerprint and cardholder challenge handling. docs: https://docs.connexpay.com/docs/3d-secure-sales-authentication - id: psd2-sca conforms: null evidence: EU-specific 3-D Secure process flow and payload documentation exists for EU clients, which is the SCA-bearing surface, but ConnexPay makes no explicit PSD2 conformance claim. docs: https://docs.connexpay.com/docs/3d-secure-payload-response-for-eu-clients-using-connexpay-solution - id: avs-cvv conforms: true evidence: Publishes the full AVS response-code table and CVV response handling, with sandbox zip codes that simulate each AVS result. docs: https://docs.connexpay.com/docs/avs-and-cvv-responses - id: nacha-ach conforms: true evidence: ACH sales and ACH credit payouts with NOC (notification of change) and return events in the webhook catalog; documented 3:00 PM EST cutoff and overnight processing. USD merchant accounts only. - id: iso-4217-currency conforms: true evidence: Currency and region code reference published for the currencyCode field on Issue Card and Issue Lite. docs: https://docs.connexpay.com/reference/currency-and-region-codes - id: iso-8583-mcc conforms: true evidence: Merchant Category Code restrictions are a first-class card control; a prohibited-MCC list is published. docs: https://docs.connexpay.com/docs/prohibited-merchant-category-codes - id: pci-dss conforms: null evidence: ConnexPay markets its browser SDK and Hosted Payment Page as keeping the integrator out of PCI scope ('you will not need to store and manage sensitive customer information like credit card data'), but publishes no PCI DSS Attestation of Compliance, level, or certificate on any public page. No trust center exists (trust.connexpay.com does not resolve). docs: https://docs.connexpay.com/docs/using-our-sdk - id: code-of-conduct-payment-card-industry-canada conforms: true evidence: Publishes a Canada Complaint Handling Procedure under the Code of Conduct for the Payment Card Industry in Canada, including FCAC escalation contacts and a documented four-step investigation and response process. docs: https://www.connexpay.com/security-and-compliance regulatory: registration: ConnexPay is a registered ISO/MSP of The Central Trust Bank and MVB Bank. source: https://www.connexpay.com/security-and-compliance issuing_partners: - Monavate (EUR card programme, named in the changelog) risk_partners: - Equifax / Kount 360 (fraud decisioning) certifications_published: [] certifications_note: No SOC 2, ISO 27001, PCI DSS AOC or other named certification is published on any public ConnexPay page. probe-security-programs.py found no trust center and no vulnerability-disclosure program.