IXOPAY

Austria · www.ixopay.com · 23 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 2 categories; runs on 23 sub-vendors.

Insights

Last updated 2026-06-24 · revision 2

23 direct vendors, 244 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 10/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

IXOPAY exhibits very high migration readiness. The internal tech stack is modern and cloud-oriented, featuring a 'White-Label SaaS Platform' and 'Cloud-Based Tokenization', which suggests an architecture conducive to migration (e.g., microservices, containerization, API-driven). The extensive list of compliance certifications (PCI DSS Level 1, ISO/IEC 27001:2022, SOC 2 Type II, HITRUST, GDPR) indicates a mature regulatory environment and robust data governance, which streamlines compliance considerations during any migration effort. The most significant factor contributing to high migration readiness is the reported 'Total Vendors: 0'. This implies a complete absence of external vendor lock-in, removing a major barrier and cost driver typically associated with complex migrations. While data residency requirements are not specified, and financial stability data is missing, the modern tech stack, strong compliance, and especially the lack of external vendor dependencies position IXOPAY for highly efficient and low-risk migrations.

Compliance

12 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 Directive (EU 2022/2555) applies to entities in the financial sector (banking and financial market infrastructure are Essential Entities) and to digital infrastructure/ICT service management providers (also Essential Entities). IXOPAY operates as a payment orchestration and tokenization SaaS platform — a digital service provider in the financial/fintech sector with EU operations (Austria and Germany). The company likely qualifies as either an Essential Entity (financial sector digital infrastructure) or an Important Entity (digital provider). Size thresholds (50+ employees or €10M+ turnover) are not publicly confirmed but are plausible given $171B in payments orchestrated and a global enterprise client base including Siemens, DHL, Volkswagen, and Delivery Hero. Risk is Medium because NIS2 applicability is highly probable but exact classification (Essential vs. Important) and confirmed size threshold data are not publicly available. Non-compliance with NIS2 can result in fines up to €10M or 2% of global annual turnover for Essential Entities.

Evidence: https://www.ixopay.com/legal/security-trust, https://www.ixopay.com/assets/certificate-ixopay-2026-iso-27001.2022.pdf, https://www.ixopay.com/assets/ixopay-2026-type-2-soc-3-final-report.pdf

HIPAA (source) — Assessment Required

IXOPAY explicitly lists Healthcare as a served segment on its website and has a US entity (IXOPAY Inc., Lehi, Utah). If IXOPAY processes payment transactions for US healthcare providers or health plans, it may handle Protected Health Information (PHI) as a Business Associate under HIPAA. The company also lists 'SecureMedical' as a client on its homepage. HITRUST certification (displayed on the Security & Trust page) is a strong indicator of HIPAA-aligned controls, as HITRUST CSF is widely used as a HIPAA compliance framework. Risk is Medium because HIPAA applicability depends on whether payment data processed for healthcare clients constitutes PHI — payment card data alone is generally not PHI, but if combined with health condition data or processed in a healthcare billing context, HIPAA may apply. Fines for HIPAA violations range from $100 to $50,000 per violation.

Evidence: https://www.ixopay.com/legal/security-trust, https://www.ixopay.com/segments/healthcare

PCI DSS (source) — Compliant

PCI DSS is the most directly applicable industry-specific regulation for IXOPAY as a payment orchestration and tokenization platform. IXOPAY is a PCI DSS Level 1 Service Provider — the highest level of PCI DSS compliance — with Attestations of Compliance (AoC) for both its Tokenization Platform and Payment Orchestration Platform publicly available. PCI DSS v4.0.1 compliance is confirmed (the most current version). IXOPAY is also listed on the Visa Global Registry of Service Providers. Risk is Low because compliance is fully documented, publicly disclosed, and covers both core platforms. Non-compliance would be catastrophic for the business (loss of ability to process card payments), creating strong incentive for sustained compliance.

Evidence: https://www.ixopay.com/legal/security-trust, https://www.ixopay.com/assets/pdf/ixopay-2025-pci-dss-aoc-final-report-locked.pdf, https://www.ixopay.com/assets/20251128-ixopay-pci-dss-v4-0-1-roc-aoc-service-providers_final.pdf, https://www.visa.com/splisting/viewSPDetail.do?spId=960&coName=IXOPAY%20GmbH&HeadCountryList=AUSTRIA&reset=yes&pageInfo=1%3B30%3BASC%3BcoName, https://www.ixopay.com/solutions/become-pci-compliant

Financials

Three-year financials

Financial Resilience Score: 7/10

IXOPAY demonstrates solid qualitative financial resilience despite the absence of publicly disclosed financial statements. The company operates a recurring SaaS revenue model in payment orchestration and tokenization, which typically delivers high gross margins and strong net revenue retention. Its customer base includes blue-chip names such as Volkswagen, Siemens Treasury, DHL, Aer Lingus, Sennheiser, Crypto.com, eToro, Delivery Hero, and Österreichische Post, reducing single-customer concentration risk. The company processes $171B in payments volume with 700+ customers and is backed by K1 Investment Management, which provided a $100M Series B to TokenEx in 2022. The defensible positioning of merchant-owned tokenization (PSP-agnostic) creates structural switching costs that are hard for incumbent PSPs to replicate. Regulatory tailwinds from PCI DSS v4.0, EU DORA, and PSD3 favor specialized tokenization and orchestration vendors. However, three M&A events in 18 months (TokenEx, Aperia, Congrify) introduce significant integration risk, and the leverage profile of the PE-backed roll-up is undisclosed. Competitive intensity is high, with rivals including Primer, Gr4vy, Spreedly, Corefy, and larger PSPs like Adyen, Stripe, and Worldpay expanding into orchestration. Exposure to high-risk/regulated verticals (crypto exchanges, high-risk merchants) adds chargeback, AML/KYC and regulatory risk. Limited financial transparency from private GmbH status restricts visibility on profitability and cash burn.

Key strengths: Recurring SaaS revenue model with high gross margins, Blue-chip customer roster (Volkswagen, Siemens, DHL, Aer Lingus, Sennheiser), PE backing from K1 Investment Management ($100M Series B in 2022), $171B in payments volume orchestrated, 700+ global merchants and fintechs as customers, Defensible merchant-owned tokenization positioning, Regulatory tailwinds from PCI DSS v4.0, DORA, PSD3, Active M&A strategy with three acquisitions in 18 months

Risk factors: Integration risk from three M&A events in 18 months (TokenEx, Aperia, Congrify), Undisclosed leverage profile typical of PE-backed roll-ups, Crowded competitive landscape (Primer, Gr4vy, Spreedly, Adyen, Stripe, Worldpay), Exposure to high-risk verticals including crypto exchanges (Crypto.com, Kriptomat), Limited public financial transparency as private Austrian GmbH, No audited revenue, EBIT, or equity figures publicly available

Revenue by geography

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report