Industry solution

PSD2 compliance, built in.

Strong Customer Authentication for European fintechs — passkeys, biometrics, and dynamic linking, all under half a second. No SMS, no friction, no regulatory headaches.

Request compliance reviewView security overview
Compliance

Regulatory certifications

SCA and dynamic linking are fully implemented. Final regulatory assessments in progress.

In progress

PSD2 / SCA

EU Payment Services Directive 2 compliance. Strong Customer Authentication, dynamic linking, and transaction monitoring are implemented. Final regulatory assessment with competent authority scheduled. Estimated completion: Q2 2027.

Planned

eIDAS

EU electronic identification and trust services regulation. Qualified Web Authentication certificates for passkeys under eIDAS Article 24. Integration with national eID schemes in progress.

Compliant by proxy

PCI DSS

Vorht does not store, process, or transmit cardholder data — authentication only. Our infrastructure is hosted on PCI DSS Level 1 certified AWS services. No card data touches our systems.

Requirements

PSD2 SCA — how we deliver it

Strong Customer Authentication

Meet PSD2's SCA requirement with passkeys and biometrics. Every transaction over EUR 30 and every login from a new device triggers multi-factor authentication — passkeys + one-time codes via WhatsApp or Telegram.

Dynamic linking

Authentication codes are cryptographically bound to the transaction amount and payee. A code generated for EUR 50 to Merchant A cannot be reused for a different transaction — required under PSD2 Article 97.

Transaction risk analysis

Real-time risk scoring on every authentication attempt. Device fingerprinting, behavioral biometrics, and geographic anomaly detection feed into an automated risk engine that adjusts authentication requirements per transaction.

Cross-border compliance

PSD2 applies across the EEA. Our edge network routes authentication through EU-based data centers (eu-west-1) by default. Data never leaves the EEA for European customers — no Schrems II concerns.

Sub-500ms SCA

Regulatory compliance doesn't have to mean friction. Our PSD2-compliant authentication flows complete in under half a second — faster than any SMS-based 3D Secure. Higher conversion, lower abandonment.

Exemption optimization

Not every transaction requires SCA. We automatically apply PSD2 exemptions where eligible — low-value transactions, trusted beneficiaries, recurring payments, corporate payments — reducing friction without sacrificing compliance.

Framework

PSD2 RTS — article by article

How Vorht maps to each requirement of the PSD2 Regulatory Technical Standards on SCA and common and secure communication.

Knowledge (something you know)Passwords, PINs — supported for legacy workflows, not required
Possession (something you have)Passkeys stored in device secure enclave, one-time codes via WhatsApp or Telegram
Inherence (something you are)Face ID, Touch ID, Windows Hello — WebAuthn biometric verification
Dynamic linkingTransaction amount + payee bound to authentication code — Article 97 compliant
Exemptions engineAutomatic application of low-value, trusted beneficiary, recurring, and corporate exemptions
Transaction monitoringReal-time risk scoring, device fingerprinting, geographic anomaly detection
Third-party provider accessDedicated interface for AISPs and PISPs — no screen scraping, no credential sharing
Secure communicationTLS 1.3 with mutual authentication for all TPP-to-bank communications

Ship PSD2-compliant auth this quarter.

Our compliance team will walk you through the technical architecture and regulatory timeline.

Talk to our fintech team