Managed Cloud
Use Transaqo through an environment operated and maintained as part of the agreed service.
Faster path to an operated environmentDeployment Options
Choose a managed, dedicated, private-cloud, or on-premises environment according to your infrastructure strategy, operational capacity, and security requirements.
Infrastructure, security and operating responsibilities are defined before production implementation.
One Platform, Multiple Deployment Models
Payment infrastructure does not have to be limited to a shared software environment. The appropriate model depends on transaction volume, isolation requirements, internal DevOps capacity, data strategy, availability needs, and the selected payment-data architecture.
Use Transaqo through an environment operated and maintained as part of the agreed service.
Faster path to an operated environmentReserve application infrastructure for one client with greater control over resources and release planning.
Stronger technical separationRun the platform inside a cloud account or private network controlled by your organization.
Established cloud and security teamsDeploy within compatible containerized infrastructure directly controlled by your organization.
Strict infrastructure-control requirementsManaged Cloud
A managed deployment is suitable for businesses that want Transaqo to coordinate the platform environment as part of the agreed service. The final hosting region, service levels, security responsibilities, and support scope are defined for the individual implementation.
Best suited for: merchants, digital platforms, and payment businesses seeking a faster path to an operated environment.
Dedicated Environment
A dedicated deployment can provide greater control over resource allocation, configuration, release planning, network policies, and integration with client-specific systems.
Depending on the agreed scope, the environment may be operated by Transaqo, jointly managed, or transferred into infrastructure controlled by the client.
Best suited for: larger merchants, PSPs, payment platforms, and organizations requiring stronger technical separation.
Private Cloud
A private-cloud deployment can be designed around the client's infrastructure standards, network controls, secrets management, observability tools, databases, and access policies.
The client retains greater control over the hosting environment while Transaqo can support platform configuration, integration work, technical implementation, and ongoing services according to scope.
Best suited for: organizations with established cloud infrastructure and internal platform or security teams.
On-Premises & Client-Hosted
The platform can be implemented in a compatible containerized environment, including a suitable Kubernetes-based infrastructure. The client controls hosting, databases, network boundaries, access policies, and operational tooling.
Transaqo can assist with deployment design, configuration, connector integration, customization, testing, updates, and support according to the agreed service scope.
Best suited for: payment companies, financial institutions, and enterprises with strict infrastructure-control or internal-hosting requirements.
Responsibility Model
Deployment ownership and operational responsibility are not the same thing. The parties should agree who operates each part of the environment, how updates are released, and how incidents and recovery are handled.
The table below is a scoping guide, not a fixed allocation. The final model depends on the selected environment, service scope, internal capacity, and production architecture.
| Responsibility area | Managed cloud | Dedicated | Private cloud | Client-hosted |
|---|---|---|---|---|
| Cloud or physical infrastructure | Service scope Coordinated within the managed service. | Agreed model Transaqo-operated, joint, or transferred. | Client control Inside the client's account or network. | Client control Owned or appointed by the client. |
| Containers / Kubernetes | Service scope Operated as part of the environment. | Agreed model Defined for the dedicated environment. | Client control Aligned with internal platform standards. | Client control Client supplies compatible infrastructure. |
| Databases and data retention | Service scope Configuration and retention are agreed. | Agreed model Designed for the isolated environment. | Client control Uses client standards and policies. | Client control Client operates the data layer. |
| Encryption, keys and secrets | Defined scope Architecture and responsibilities are agreed. | Agreed model Controls follow the selected operating model. | Client control Integrates with client key and secrets tooling. | Client control Client manages infrastructure-level controls. |
| Monitoring and alerting | Service scope Included according to selected service. | Agreed model Transaqo, joint, or client monitoring. | Client-led Can use established observability tools. | Client-led Client operates underlying monitoring. |
| Backups and recovery | Service scope Backup configuration is agreed. | Agreed model Recovery ownership is defined. | Client-led Aligned with client recovery procedures. | Client-led Client supplies and operates recovery tooling. |
| Platform updates and patching | Coordinated Routine updates under service scope. | Release plan Planned for the dedicated environment. | Release plan Coordinated with client change controls. | Release plan Applied through the agreed update process. |
| Incident response and support | Service scope Support and response arrangements are defined. | Shared plan Roles follow the operating model. | Shared plan Client infrastructure and platform roles differ. | Shared plan Client leads infrastructure response. |
| Connector maintenance | Support scope Maintained according to the Transaqo service. | Support scope Defined in the implementation agreement. | Support scope Platform support remains separately scoped. | Support scope Separate from infrastructure ownership. |
A client-hosted deployment provides greater infrastructure control, but it also requires sufficient operational capacity from the client or an appointed infrastructure partner.
Payment-Data Architecture
Payment credentials may be handled through a managed vault, a client-controlled compliant environment, or an eligible external vault provider.
The appropriate configuration depends on where sensitive payment information is collected, transmitted, tokenized, and stored. PCI DSS responsibilities and other compliance obligations must be assessed for the complete production architecture.
Compliance scope follows the complete payment-data flow—not the hosting label alone. The final configuration should be assessed before production.
Test
Production
Designed for Production Growth
Production architecture can be designed around expected transaction volumes, peak traffic, availability requirements, geographic coverage, and the dependencies introduced by connected providers.
No generic production template: the final architecture is defined during technical discovery for the selected deployment and operating model.
Architecture & Deployment
Discuss your hosting preferences, internal capabilities, security requirements, and expected payment volumes with the Transaqo team.