White-label softPOS · TMS · SDK

Every Android device can become a terminal.
You run the whole fleet.

SoftFleet is the white-label softPOS platform for acquirers, ISOs and SDK providers — the app, the integration SDK, and the console that gives every device an identity, a heartbeat and an audit trail. Card data never touches it.

0card numbers stored
5-stage device lifecycle
≤3 moenforced update cadence
fleet · overview live
TID·9F2C-04A1
Ferry Building Coffee — San Francisco
v4.2.1 operating
TID·B71E-2288
Mission Dolores Tacos — location 2
v4.2.1 operating
TID·5A0D-77C3
Marina Bloom Florist
v4.2.0 key rotating
TID·C4F9-1130
Presidio Provisions — pop-up
v4.2.1 enrolled
attested · Ed25519 · P-256
The boundary

Not a payment switch. Card data never reaches it.

Capture, SRED and PIN entry stay inside the PCI-MPoC-certified SDK on the device. SoftFleet owns everything around the payment — so a breach of the backend is never a breach of a card.

whoDevice identity, enrollment, attestation and revocation
stateFleet health, versions and anomalies, live
recordTransactions, signed receipts and an append-only audit trail
accessDeny-by-default RBAC, tenant-scoped to each partner
The platform

Four parts, one white-label stack.

Ship card acceptance under your own brand, and manage the estate it creates — from a single console, with the security model built in.

White-label softPOS app

Your brand, on ordinary Android phones and tablets. Tap-to-pay with no dedicated hardware, themed per merchant and mirrored across every terminal in the fleet.

  • Merchant-level branding, logo and receipt theme
  • MPoC-certified card boundary inside the app
  • Server-enforced minimum version, remote kill-switch

Integration SDK

Drop card acceptance into an app you already ship. The certified capture boundary comes with it; you keep your own checkout, your own UX, your own users.

  • Native Android SDK with a stable command contract
  • Intent adapter to normalize provider results
  • No PAN, PIN or track data ever crosses into your code

SoftFleet TMS & console

Enrollment, device identity, health telemetry, transactions, signed receipts, RBAC and audit — one console for the whole estate, scoped per partner.

  • Live fleet view: health, versions, anomalies
  • Two-step login — passkey or TOTP, argon2id
  • CRM & boarding integration, outgoing webhooks

MDM integrations New

Device management alongside terminal management. Wire fleet enrollment, lock, wipe and policy to the MDM vendors your customers already run.

  • Leading MDM vendors, one integration surface
  • Enrollment and revocation kept in step with the TMS
  • Rolling out next — talk to us about your stack
Device identity

A terminal ID identifies. The key authenticates.

No shared secret ships in the binary. Each install provisions a hardware-backed key at enrollment, and every device is independently revocable through one real lifecycle.

STAGE 01
Announced

The terminal ID is allow-listed and bound to a merchant. An ID alone never grants access — it only scopes.

STAGE 02
Enrolled

Platform attestation — App Attest, Play Integrity — gates a hardware-backed key pair. The private key never leaves the device.

STAGE 03
Operating

Every request is signed and replay-protected. A valid key paired with a foreign terminal ID is a theft signal — rejected.

STAGE 04
Rotated

Keys roll with zero downtime: the old and new overlap under one terminal ID, and the old is retired at usage zero — measured, not assumed.

STAGE 05
Revoked

A lost or compromised device is revoked on its own, audit-logged. A fleet-wide version kill-switch hard-refuses stale installs.

Who it's for

Built for the people who run the estate.

One platform, three vantage points — each sees exactly its own slice, enforced server-side, never by a hidden menu item.

Acquirer · Operator

Own the whole fleet

Board merchants, issue terminals and see every device, transaction and receipt across the platform. The MDM layer runs beside it.

Sales partner · ISO

Your merchants, scoped

Board and support your own merchants, run receipt-marketing campaigns for them, and never reach another partner's data — row-scoped by design.

softPOS SDK provider

Ship the SDK, skip the TMS build

Let SoftFleet run device identity, health, receipts and audit under your brand, so you invest in card acceptance — not fleet plumbing.

Security & compliance

Secure because it holds less, not because it hides more.

The backend is designed so the sensitive things simply aren't there to leak — and everything that is there is encrypted, attributed and revocable.

No PAN, ever

Card data stays in the SDK

Capture, SRED and PIN entry live inside the PCI-MPoC-certified boundary. The backend never sees, logs or re-encrypts a card number.

Encrypted

At rest and in transit

Field-level encryption for PII, TLS on every hop including internal ones, and rotatable signing secrets — no secret assumed permanent.

Strong auth

Passkeys, TOTP, argon2id

Two-step console login with phishing-resistant passkeys or TOTP, breached-password screening and server-invalidatable sessions.

Attributed

Append-only audit trail

Every action, sensitive read and auth event is logged with masked before/after — and always resolves back to a named person.

Least privilege

Deny-by-default RBAC

Roles carry permissions, users carry roles, and every request is object-scoped — a tenant can never reach another's terminals.

Revocable

Per-device kill-switch

Any device is revoked on its own; an enforced update cadence lets the fleet hard-refuse outdated or attestation-failing installs.

Get started

Put your brand on tap-to-pay — and keep the fleet in view.

See the console, the SDK and the device-identity model on a live walkthrough tailored to your program.