Skip to content
MILETIA
Menu

Technology and security

Payment cryptographic infrastructure consumed by API, deployed in the client’s cloud environment and operated by MILETIA.

Deployment model

The environment is the client’s

Sovereignty

The CaaS is deployed in the contracting party’s cloud tenant. Data, infrastructure and cloud billing stay under the client’s ownership; MILETIA operates the service.

HSM to match the environment

AWS · Azure

The HSM core runs on cloud payment-cryptography services — available on AWS and Azure, matching the client’s strategy — always on FIPS 140-2 Level 3 certified hardware under the providers’ compliance programmes.

Consumed by API

REST · gRPC

The client’s authoriser calls the CaaS to validate transactions; the back office calls the CaaS to create and manage cards. Per-issuer access governance, with individual credentials, limits and metrics.

Cost transparency

Predictable

Infrastructure costs on the client’s own cloud bill; a separate, predictable service fee.

Foundation

Consumption
High-performance REST and gRPC APIs in the authorisation flow
Cloud
AWS and Azure — in the client’s tenant
HSM
FIPS 140-2 Level 3 certified hardware
Keys
TR-31 key blocks · dual control · split knowledge
Isolation
Per-issuer governance: individual credentials, limits and metrics
Scale
Multi-tenancy validated under load: 1,500 TPS, p95 < 50 ms

Security and compliance

Conformity by design and operation

The CaaS is designed and operated in conformity with PCI-DSS v4.0.1 and PCI-PIN requirements. Every key and PIN operation runs entirely inside FIPS 140-2 Level 3 certified payment HSMs, with TR-31 key blocks, dual control and split knowledge in key ceremonies.

Reducing the issuer’s PCI scope

Sensitive data stays concentrated in the service perimeter, and client systems interact through APIs that dispense contact with the real data. Specialised operation — key ceremonies, HSM management, bureau integration — stays with MILETIA, with no upgrade projects on the client side.

The cloud components in use operate under the respective providers’ compliance programmes, including datacenter PCI DSS.