generated: '2026-07-17' method: searched source: - https://www.hitpayapp.com/security - https://docs.hitpayapp.com/apis notes: >- Standards / compliance posture. Compliance claims (PCI DSS, MAS regulation) are searched from HitPay's site and docs; API-shape standards are derived from openapi/hitpay-openapi-original.json. standards: - id: pci-dss conforms: true evidence: >- HitPay states PCI-DSS compliance; hosted checkout and Drop-In UI keep card data off the merchant server (docs + www.hitpayapp.com/security). - id: mas-mpi conforms: true evidence: >- Regulated by the Monetary Authority of Singapore as a Major Payment Institution (MPI); regulated across multiple APAC jurisdictions. - id: oauth2 conforms: false evidence: API-key (X-BUSINESS-API-KEY) auth only; no OAuth2/OIDC. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: Errors are plain JSON; no application/problem+json responses. - id: rfc8594-sunset conforms: false evidence: No Sunset/Deprecation header policy published. - id: hmac-webhook-signing conforms: true evidence: >- Webhook authenticity via HMAC-SHA256 (Hitpay-Signature header for event webhooks; hmac field for legacy callbacks). compliance_program: published: true page: https://www.hitpayapp.com/security certifications: - PCI DSS regulatory: - MAS Major Payment Institution (Singapore) - Multi-jurisdiction APAC payment regulation note: >- See security/hitpay-trust-center.yml for the full trust posture. No public SOC 2 / ISO 27001 report portal was confirmed on probe.