Anonymised under NDA
PCI DSS Level 1 payments gateway and cashier aggregating 100+ providers
Payments · Platforms integrating through a single cashier API
Our second-largest system: a payments gateway and cashier that aggregates more than 100 payment providers, including Paysafe, Nuvei, Rapyd, TrueLayer, and Bolt, behind one API, with routing rules, closed-loop payouts, and hosted cashier surfaces, certified to PCI DSS Level 1.
The problem
- Every platform that wanted to accept payments was integrating providers one at a time, each with its own API, settlement model, and compliance obligations.
- Adding or switching a provider was a project, so operators stayed with underperforming providers rather than absorb the engineering cost of change.
- Handling card data directly put the full weight of PCI DSS on each platform rather than on a certified layer built for it.
The architecture
- A single cashier API for the integrating platform, with provider-specific adapters behind it. A new provider is added by entering its credentials, not by writing code.
- Routing rules select the provider per transaction on geography, method, amount, cost, and success rate, with automatic failover.
- Closed-loop payouts: withdrawals return to the instrument the deposit came from, satisfying provider and regulatory rules by default.
- Every integration surface: hosted iframe cashier, embeddable widgets, direct APIs, and server-to-server for platforms with their own front end.
- Certified to PCI DSS Level 1, so card data is tokenised inside the gateway and never touches the integrating platform.
AWSPaysafeNuveiRapydTrueLayerBoltTokenisation3-D Secure
The outcome
- Platforms integrate once and gain access to the whole provider network, choosing and re-routing providers by configuration.
- Card-data scope moves off the integrating platform and onto the certified gateway.
Services drawn on
A similar problem on your roadmap?
A Discovery Sprint is the fastest path to a scoped, costed proposal.