Security & compliance

Security and compliance at AgentaOS

AgentaOS is not a bank and does not hold merchant funds itself. Regulated payment, e-money and custody services are provided by licensed Payment Partners holding Electronic Money Institution (EMI) or Payment Service Provider (PSP) licences. Card data is captured and stored by PCI DSS compliant payment partners and never touches AgentaOS servers.

Card data and PCI DSS

Card details are collected directly by our PCI DSS compliant payment partners through their own hosted fields. AgentaOS never sees, transmits or stores a full primary account number. Because of this, merchants integrating the AgentaOS checkout do not bring their own systems into PCI scope.

Where money sits

Proceeds from card sales are held on regulated, licensed rails through our Payment Partners until payout. Merchant balances are not commingled with AgentaOS operating funds. Payouts are made to the merchant's own bank account in EUR or USD on a twice-monthly schedule, subject to verification and any applicable reserve. New accounts have an incoming clearance period of approximately 14 days.

Data protection and GDPR

Aristokrates OU is an EU-established controller for its own processing and a processor for merchant customer data. We publish a Data Processing Agreement containing Article 28 terms and annexes covering processing details, security measures and sub-processors, and a Privacy Policy covering lawful bases, retention periods and international transfers.

Fraud and disputes

Because AgentaOS is the merchant of record, chargebacks are filed against Aristokrates OU rather than against the merchant. We run pre-authorisation fraud screening, support 3D Secure and Strong Customer Authentication at no charge, and contest illegitimate disputes with the card networks. See the Merchant Terms for how dispute costs are allocated.

The legal entity

Legal nameAristokrates OU
Registry code16948108
EU VAT numberEE102810130
JurisdictionEstonia, European Union
Registered officeTallinn, Estonia
RoleMerchant of Record and seller of record on every card sale

This is the entity that appears on your buyer's invoice, card statement and receipt, and the entity that carries the chargeback liability.

Bank-grade security. Card data is handled entirely by our PCI DSS compliant payment partners and never touches AgentaOS servers. Your balance is held by licensed EU e-money institutions, and all data is encrypted in transit and at rest.

Reporting a security issue

Email [email protected]. We aim to acknowledge reports within two business days.

Last updated .