generated: '2026-07-19' method: derived source: https://developer.epoint.az/en (docs) + https://github.com/rafoabbas/epoint-php (SDK) note: >- Derived from the published developer docs and endorsed SDK. Epoint publishes no formal compliance certifications page (no SOC 2 / ISO 27001 / PCI DSS attestation document was found), so no `Compliance` pointer is emitted; the PCI reference below is the SDK's tokenization claim, not a published certificate. standards: - id: oauth2 conforms: false evidence: Custom public_key + SHA1 signature scheme; no OAuth flows. - id: oidc conforms: false evidence: No /.well-known/openid-configuration (404). - id: rfc9457-problem-details conforms: false evidence: Errors use a custom {status, code, message, trace_id} envelope, not application/problem+json. - id: rfc8594-sunset conforms: false evidence: No Sunset/Deprecation header support documented. - id: iso8583-response-codes conforms: true evidence: Bank response codes follow the ISO-8583-style 000/1xx/2xx/3xx scheme (errors/epoint-decline-codes.yml). - id: 3d-secure conforms: true evidence: Card entry and authentication occur on the acquiring bank's 3-D Secure hosted page. - id: pci-dss-tokenization conforms: unverified evidence: >- The endorsed PHP SDK describes card registration as "PCI-compliant tokenization" and cardholder data is entered on the bank's hosted page, but Epoint publishes no PCI DSS attestation document. - id: apple-pay conforms: true evidence: Documented Apple Pay support via the token widget. - id: google-pay conforms: true evidence: Documented Google Pay support via the token widget.