The licence position
Next Payment is a technology provider. Payment instructions are processed and settled by the applicable licensed partner, under that partner's licence, in its own name, on a timeline set by the route, the cutoffs and the partner's checks. Availability is a property of the partner and the corridor, not of this software.
Partners are not named on this site. That is a rule, not an oversight: naming one partner would imply that it covers every corridor we quote, and it does not. The licence position for a specific corridor is confirmed during onboarding, before any payment is instructed.
Approval
Every release is confirmed by a named person using a FIDO security key. The confirmation is bound to a locked version of the payment: change the recipient, amount, currency, rate or charges, and the payment returns for a fresh review rather than proceeding on the old approval. The signature is verified against the key; it is not a code that can be replayed, and the console holds no key material of its own.
What the software will not do
The console and the MCP endpoint read and draft. Neither exposes release_funds, approve, policy:write or wallet:sign — those verbs are listed as prohibited in the endpoint's own descriptor, so an AI client cannot reach them even if it asks. A release path that has no named human approver does not exist in this product.
Certifications
| Standard | State | What that means |
| ISO/IEC 27001 | Planned | Not certified. No audit date is published yet; this line changes when the certificate is issued, with its number and certification body. |
| SOC 2 | Not held | Stated only if it becomes true. |
| PCI DSS | Not applicable | Card issuing and card acceptance are not part of the service, so cardholder data is not processed here. |
No certification badge appears anywhere on this site until the certificate exists.
Data handling
What is true today, and checkable: the workspace talks only to this deployment's own API, no third-party analytics or advertising script runs on any page, and the data the console shows is the data your own workspace holds.
The detail a procurement questionnaire asks for — hosting regions, retention windows, encryption specifics, backup and recovery, the incident-response process and the sub-processor list — is not published on this page yet. It is being written as it is confirmed rather than estimated, and it will appear here rather than in a PDF that cannot be checked.
Report a security issue
Email hello@hashcode-next.com with the subject line Security report. Please include what you observed and how to reproduce it; do not include live customer data, and do not test against a workspace you do not own.
Last reviewed 2 October 2026. Where this page and a marketing line disagree, this page is the one we hold ourselves to.