Deployment Options

Deploy Payment Infrastructure on Your Terms

Choose a managed, dedicated, private-cloud, or on-premises environment according to your infrastructure strategy, operational capacity, and security requirements.

transaqo · deployment topology
Transaqo orchestration layer One platform
Connectors Routing Operations APIs
ManagedCloudOperated within the agreed service scope
IsolatedDedicatedEnvironment reserved for one client
ControlledPrivate cloudInside the client's cloud account or network
Client-hostedOn-premisesInside infrastructure controlled by the client

Infrastructure, security and operating responsibilities are defined before production implementation.

One Platform, Multiple Deployment Models

Choose the level of infrastructure control that fits your organization.

Payment infrastructure does not have to be limited to a shared software environment. The appropriate model depends on transaction volume, isolation requirements, internal DevOps capacity, data strategy, availability needs, and the selected payment-data architecture.

01 · OPERATED

Managed Cloud

Use Transaqo through an environment operated and maintained as part of the agreed service.

Faster path to an operated environment
02 · ISOLATED

Dedicated Environment

Reserve application infrastructure for one client with greater control over resources and release planning.

Stronger technical separation
03 · PRIVATE

Private Cloud

Run the platform inside a cloud account or private network controlled by your organization.

Established cloud and security teams
04 · CLIENT-HOSTED

On-Premises

Deploy within compatible containerized infrastructure directly controlled by your organization.

Strict infrastructure-control requirements

Managed Cloud

Focus on payment operations, not the complete infrastructure stack.

A managed deployment is suitable for businesses that want Transaqo to coordinate the platform environment as part of the agreed service. The final hosting region, service levels, security responsibilities, and support scope are defined for the individual implementation.

  • Platform deployment
  • Application configuration
  • Routine software updates
  • Infrastructure monitoring
  • Backup configuration
  • Scaling arrangements
  • Environment maintenance
  • Technical support

Best suited for: merchants, digital platforms, and payment businesses seeking a faster path to an operated environment.

Managed environmentAgreed service scope
ApplicationConfiguration and platform servicesCoordinated
OperationsMonitoring, backups and maintenanceScoped
CapacityScaling arrangements and environment planningDefined
SupportTechnical support under selected serviceAgreed

Dedicated Environment

Reserve application infrastructure for one organization.

A dedicated deployment can provide greater control over resource allocation, configuration, release planning, network policies, and integration with client-specific systems.

Depending on the agreed scope, the environment may be operated by Transaqo, jointly managed, or transferred into infrastructure controlled by the client.

  • Single-client environment
  • Resource allocation
  • Client-specific configuration
  • Release planning
  • Network policies
  • System integrations

Best suited for: larger merchants, PSPs, payment platforms, and organizations requiring stronger technical separation.

Dedicated environmentOne client
Application tierReserved services and client configurationIsolated
Data tierEnvironment-specific database designDefined
NetworkPolicies aligned with implementation needsAgreed
OperationsTransaqo, joint, or client-controlled modelScoped

Private Cloud

Run Transaqo inside your cloud account or private network.

A private-cloud deployment can be designed around the client's infrastructure standards, network controls, secrets management, observability tools, databases, and access policies.

The client retains greater control over the hosting environment while Transaqo can support platform configuration, integration work, technical implementation, and ongoing services according to scope.

  • Client cloud account
  • Private network controls
  • Client secrets management
  • Existing observability tooling
  • Client database standards
  • Internal access policies

Best suited for: organizations with established cloud infrastructure and internal platform or security teams.

Client cloud accountPrivate deployment
NetworkClient VPC, routing and access controlsClient
SecretsClient-selected keys and secrets toolingClient
PlatformTransaqo configuration and implementation supportScoped
OperationsDefined around internal team capabilitiesAgreed

On-Premises & Client-Hosted

Keep the underlying infrastructure under your direct control.

The platform can be implemented in a compatible containerized environment, including a suitable Kubernetes-based infrastructure. The client controls hosting, databases, network boundaries, access policies, and operational tooling.

Transaqo can assist with deployment design, configuration, connector integration, customization, testing, updates, and support according to the agreed service scope.

  • Client-controlled hosting
  • Container or Kubernetes environment
  • Databases and retention
  • Network boundaries
  • Access and security policies
  • Operational tooling

Best suited for: payment companies, financial institutions, and enterprises with strict infrastructure-control or internal-hosting requirements.

Client-hosted environmentInfrastructure control
ComputeCompatible containerized infrastructureClient
DataDatabases, retention and recovery toolingClient
NetworkBoundaries, access policies and connectivityClient
TransaqoPlatform implementation, updates and supportScoped

Responsibility Model

Define ownership before production implementation.

Deployment ownership and operational responsibility are not the same thing. The parties should agree who operates each part of the environment, how updates are released, and how incidents and recovery are handled.

The table below is a scoping guide, not a fixed allocation. The final model depends on the selected environment, service scope, internal capacity, and production architecture.

Responsibility areaManaged cloudDedicatedPrivate cloudClient-hosted
Cloud or physical infrastructureService scope
Coordinated within the managed service.
Agreed model
Transaqo-operated, joint, or transferred.
Client control
Inside the client's account or network.
Client control
Owned or appointed by the client.
Containers / KubernetesService scope
Operated as part of the environment.
Agreed model
Defined for the dedicated environment.
Client control
Aligned with internal platform standards.
Client control
Client supplies compatible infrastructure.
Databases and data retentionService scope
Configuration and retention are agreed.
Agreed model
Designed for the isolated environment.
Client control
Uses client standards and policies.
Client control
Client operates the data layer.
Encryption, keys and secretsDefined scope
Architecture and responsibilities are agreed.
Agreed model
Controls follow the selected operating model.
Client control
Integrates with client key and secrets tooling.
Client control
Client manages infrastructure-level controls.
Monitoring and alertingService scope
Included according to selected service.
Agreed model
Transaqo, joint, or client monitoring.
Client-led
Can use established observability tools.
Client-led
Client operates underlying monitoring.
Backups and recoveryService scope
Backup configuration is agreed.
Agreed model
Recovery ownership is defined.
Client-led
Aligned with client recovery procedures.
Client-led
Client supplies and operates recovery tooling.
Platform updates and patchingCoordinated
Routine updates under service scope.
Release plan
Planned for the dedicated environment.
Release plan
Coordinated with client change controls.
Release plan
Applied through the agreed update process.
Incident response and supportService scope
Support and response arrangements are defined.
Shared plan
Roles follow the operating model.
Shared plan
Client infrastructure and platform roles differ.
Shared plan
Client leads infrastructure response.
Connector maintenanceSupport scope
Maintained according to the Transaqo service.
Support scope
Defined in the implementation agreement.
Support scope
Platform support remains separately scoped.
Support scope
Separate from infrastructure ownership.

A client-hosted deployment provides greater infrastructure control, but it also requires sufficient operational capacity from the client or an appointed infrastructure partner.

Payment-Data Architecture

Coordinate deployment with checkout, vault and tokenization choices.

Payment credentials may be handled through a managed vault, a client-controlled compliant environment, or an eligible external vault provider.

The appropriate configuration depends on where sensitive payment information is collected, transmitted, tokenized, and stored. PCI DSS responsibilities and other compliance obligations must be assessed for the complete production architecture.

Checkout collection pointHosted, embedded, or client-controlled payment experience Define collection scope
Tokenization and vaultManaged, client-controlled, or eligible external provider Select vault model
Orchestration and providersRoute eligible tokenized transactions to connected providers Map data flow

Compliance scope follows the complete payment-data flow—not the hosting label alone. The final configuration should be assessed before production.

Environment architectureDesigned during technical discovery

Test

Test application services
Sandbox connectors
Separated test data

Production

Application A
Application B
Managed or client-controlled database
Logging
Monitoring
Secrets
Backups

Designed for Production Growth

Plan around volume, availability and provider dependencies.

Production architecture can be designed around expected transaction volumes, peak traffic, availability requirements, geographic coverage, and the dependencies introduced by connected providers.

  • Separated test and production environments
  • Redundant application services
  • Scalable processing components
  • Managed or client-controlled databases
  • Centralized logging and monitoring
  • Protected secrets and encryption keys
  • Backup and recovery procedures
  • Controlled release and update processes

No generic production template: the final architecture is defined during technical discovery for the selected deployment and operating model.

Architecture & Deployment

Choose the Right Infrastructure Model

Discuss your hosting preferences, internal capabilities, security requirements, and expected payment volumes with the Transaqo team.