Opinion
‘Direct to Customer’ capability increases operational trust amongst PSPs and ISOs without adding cost to their infrastructure stacks
Last month, Mypinpad revealed our new SoftPOS platform Maple is now delivering a median merchant wait time of 1.3 seconds using MPoC, with 80% of our customers’ transactions completing in 2.6 seconds or less.
So, if sufficient transaction speed can be achieved within MPoC compliant payment infrastructures using a ‘SoftPOS First’ strategy, what more is there to do to persuade the largest acquirers and PSPs to make the switch to SoftPOS?

For large acquirers, there is an operational risk from contracting with an SMB-sized paytech for SoftPOS provision. Yet many of the best SoftPOS providers are relatively small operations. Acquirers must put their selected SoftPOS provider prospects through thorough risk management and cybersecurity tests — making an already complex tender and contract process to sign them up all the harder and lengthier.
The largest threats which need to be mitigated before these deals can be signed include:
- Downtime resulting in failed transactions and lost revenue, combined with poor merchant experience should transactions fail
- Incorrect or non-compliant handling of data resulting in fines and potential lawsuits
- Survival: will their selected SoftPOS provider be in business in five years’ time, or will they be swallowed up by a competitor or go bust?
To this end, we realised that to be a leading SoftPOS platform which could stimulate the market to adopt rapidly, we needed to build operational resilience into our platform’s design from Day 1. Indeed, regulatory thinking associated with building better resilience into critical national infrastructure is demanding this. The EU's Digital Operational Resilience Act (DORA) places considerably greater emphasis on understanding ICT third-party concentration of risk, while UK financial regulators have already begun directly overseeing tech providers whose failure could present systemic risks to the financial services sector. In July 2026, AWS, Google Cloud, Microsoft and Oracle became the first providers brought within the UK's new Critical Third Parties (CTP) regime.
Resilience in the tech world tends to be tackled in two key ways:
- Infrastructure duplication: By building redundancy into your payment infrastructure stack. Essentially, this means duplicating infrastructure elements and architecting an ability to ‘fail over’ to a duplicate system if the first supplier component fails for any reason. However, it’s too expensive to put this dedicated additional infrastructure into countries with local laws governing personal and transaction data.
- Eliminating dependency on specific infrastructure components: What PSPs and acquirers actually need is less infrastructure in the way of a transaction, together with an ability to keep transacting even when the internet goes down.
It’s also important to lower transaction latency, while ensuring country-specific compliance. Finally, transactions must be routable via your existing gateways so no new host connections for customers with PCI terminal fleets are needed.
We enable all of these capabilities via our Maple platform. For Mypinpad, it’s about ensuring that the acquirer or PSP’s payment architectures keep functioning even when individual components of that architecture have failed. As such, any single points of failure must be removable should the worst happen.
The most efficient way to do that is to offer a facility to bypass the SoftPOS back-end entirely, instead linking directly from the mobile payments app to the ISO host or payment gateway. So, we built that bypass option into our platform and called it the ‘Direct to Customer’ (or DTC) option. Since we rolled out this option, we have found it has met a real need — both reducing operational risk and containing transaction costs, while maintaining security.
Why this approach? The direction of travel is not that financial institutions should stop using small, specialist, highly innovative tech providers. It is that operational resilience requires a detailed understanding of exactly where dependencies exist and what happens if any one of them becomes unavailable. Within payment acceptance, this raises an important architectural question: if the mobile device, gateway and acquirer remain available, should failure of an intermediary SoftPOS processing layer necessarily prevent the transaction being completed? Our view is that it should not!
We uncovered three unique use cases which make our bypass option desirable, even if rarely applied:
1. Operational resilience
An interruption of our SoftPOS payment processing service no longer becomes an interruption to payment acceptance with our Direct to Customer option. Merchants can continue transacting at speed through that period, using existing devices and infrastructure, reducing operational risk considerably.
Risk is further reduced if your SoftPOS provider is certified to handle transactions offline under the MPoC standard (as we are). For us, this bypass capability helps build operational trust with the much larger PSPs and ISOs we are now working with. Some of these organisations might otherwise have been concerned about relying so heavily for a mission critical payments service on a relatively small software business like Mypinpad.
2. Data sovereignty compliance
Where national or customer rules dictate how transaction data must travel, the customer's gateway can become the direct processing destination rather than routing data unnecessarily through another territory. Our SoftPOS back-end bypass option offers a good solution where data protection laws demand local/in-region payments settlement. There is no sensitive data travelling around the world in the resulting ‘direct to gateway’ transaction. No data provision restrictions will be breached however strong data protection legislation is within specific countries.
3. Architectural control
PSPs and acquirers can retain their existing gateway, processing and acquiring infrastructure rather than surrendering control of the payment chain to their SoftPOS technology supplier.
Summary: operational resilience without additional costs
Your biggest risk in payments, like all IT and network-based systems, is downtime. To build more resilience into any system, you have two choices. You can build in additional redundancy — creating parallel systems for completing a transaction so if one fails you ‘hot swap’ to the spare or duplicate system which is on standby.
Alternatively, you develop the ability to disable and bypass perceived areas of operational risk. Mypinpad took the second option with our DTC functionality in Maple. The result is that we have been able to assure 99.999% uptime for our customers over the last 12 months, while giving them optimal control and transaction speed, all at the lowest possible risk and cost.
In addition, DTC to existing gateways doesn’t require any lab visits. We take care of all the messy MPoC compliance aspects, so the customer can continue focusing on their SoftPOS rollouts.
Talk to Us
Ready to explore what Mypinpad can do for you?
Certified. Independent. Deployed across 28 countries. Let's talk about your use case.
Get in Touch