
Strong Customer Authentication for European fintechs — passkeys, biometrics, and dynamic linking, all under half a second. No SMS, no friction, no regulatory headaches.
SCA and dynamic linking are fully implemented. Final regulatory assessments in progress.
EU Payment Services Directive 2 compliance. Strong Customer Authentication, dynamic linking, and transaction monitoring are implemented. Final regulatory assessment with competent authority scheduled. Estimated completion: Q2 2027.
EU electronic identification and trust services regulation. Qualified Web Authentication certificates for passkeys under eIDAS Article 24. Integration with national eID schemes in progress.
Vorht does not store, process, or transmit cardholder data — authentication only. Our infrastructure is hosted on PCI DSS Level 1 certified AWS services. No card data touches our systems.
Meet PSD2's SCA requirement with passkeys and biometrics. Every transaction over EUR 30 and every login from a new device triggers multi-factor authentication — passkeys + one-time codes via WhatsApp or Telegram.
Authentication codes are cryptographically bound to the transaction amount and payee. A code generated for EUR 50 to Merchant A cannot be reused for a different transaction — required under PSD2 Article 97.
Real-time risk scoring on every authentication attempt. Device fingerprinting, behavioral biometrics, and geographic anomaly detection feed into an automated risk engine that adjusts authentication requirements per transaction.
PSD2 applies across the EEA. Our edge network routes authentication through EU-based data centers (eu-west-1) by default. Data never leaves the EEA for European customers — no Schrems II concerns.
Regulatory compliance doesn't have to mean friction. Our PSD2-compliant authentication flows complete in under half a second — faster than any SMS-based 3D Secure. Higher conversion, lower abandonment.
Not every transaction requires SCA. We automatically apply PSD2 exemptions where eligible — low-value transactions, trusted beneficiaries, recurring payments, corporate payments — reducing friction without sacrificing compliance.
How Vorht maps to each requirement of the PSD2 Regulatory Technical Standards on SCA and common and secure communication.
Our compliance team will walk you through the technical architecture and regulatory timeline.