Skip to main content

Platform/Switch

03 · Switch

ISO 8583 switching
for POS estates.

Authorize and route POS card messages (SALE, VOID, REFUND) over ISO 8583 with on-us / off-us policy, terminal management, and velocity controls your operations floor can stage safely.

Built forBanks, processors, and retail acquirers running terminal estates that need switch + TMS without forklifting the core

Message standard
ISO 8583 POS authorization paths
Ops controls
TMS · velocity · staged rule rollout
Routing
On-us / off-us with auditable decisions
02 · Problem

What buyers are solving

Framed for Banks, processors, and retail acquirers running terminal estates that need switch + TMS without forklifting the core — not generic payment pain.

Legacy switch change is high blast-radius

Updating velocity or routing on the incumbent switch means weekend change windows and opaque logs.

Terminal estate without remote control

Hotlists and parameter updates require truck rolls or brittle vendor tools.

Decline storms noticed too late

Operations learns from merchant complaints instead of automatic throttle and terminal block.

03 · Flow

How it works

  1. Terminal estate

    Register terminals, keys, and merchant hierarchy.

  2. Authorize

    ISO messages validated, switched, and timed.

  3. Route

    On-us / off-us path selection with policy.

  4. Protect

    Velocity and storm controls apply before response.

  5. Operate

    EOD, settlement posture, and incident tooling.

switch · TMS · velocity rules · v37
active
01if amount_velocity_5m > 8x avg→ throttle terminal
02if decline_storm in 60s→ block terminal · alert
03if PAN in hotlist→ decline · log
04if MID + BIN low-risk→ approve · on-us route
05if MID + BIN cross-scheme→ approve · off-us route
06if * (default)→ approve · cost-min
● APPROVED14:08:21
SALE · EGP
489.50
CARD•••• 4242 · VISA
TERMTID 8KQH · MID 91823
AUTH62ms
3DSok
1
2
3
4
5
6
7
8
9
*
0
#
04 · Capabilities

Core capabilities

Each capability names a concrete mechanism — not a marketing adjective.

ISO 8583 switching

Ingest, validate, route, and respond for SALE, VOID, and REFUND with message-level audit identifiers.

On-us / off-us routing

Policy chooses issuer / acquirer path; decisions are logged for ops and scheme dispute cycles.

Terminal Management System

Remote configuration, health, hotlists, and parameter distribution across the terminal hierarchy.

Velocity & storm controls

Counters, limits, decline-storm detection, auto-throttle or terminal block with reason codes.

Staged policy rollout

Promote rules in shadow/canary scopes before full estate activation; rollback is a first-class action.

PIN / MAC key handling

PIN translation and MAC verification follow HSM policies agreed at onboarding for your certified HSM estate.

Operator reporting

EOD totals, on-us/off-us splits, decline and timeout analysis for the operations floor.

Anomaly flags for ops

Optional AI-assisted anomaly flags highlight unusual terminal clusters for human review — they do not silently rewrite production velocity limits.

Positioning

Where this sits vs alternatives

Build in-house

ISO parsing, TMS, HSM integration, and scheme certification are multi-year platforms — Switch packages the rail-side control plane beside your core.

Local incumbent switch

Incumbents often ship opaque change processes. Flagship emphasizes staged rollout, reason-coded blocks, and operator-readable routing logs.

Global orchestrator

Orchestrators optimize online PSP meshes. Switch is for POS ISO 8583 estates — a different problem than checkout routing.

05 · Architecture

Architecture and deployment

Terminals and TMS sit at the edge; the switch authorizes and routes; fraud hooks and settlement exports sit beside — core GL stays yours.

Deployment options

On-prem / private DC

Common for bank processors on supported Linux / Kubernetes baselines documented in the estate pack.

Private cloud

Dedicated switch cluster in your chosen region(s).

Hybrid

TMS/control in cloud with latency-sensitive auth on-prem — the standard hybrid reference pattern.

  • HA/DR options from hot-standby to active-active with geographic failover; RTO/RPO stated per estate.
  • Auth-log and PII residency follows the estate deployment and DPA data-class map.
  • Does not replace core banking or the GL — ledgering stays downstream.
06 · Integration

Integration experience

Integration is terminal + host message profiles, not a single REST call. REST helpers below are illustrative for lab tooling.

Illustrative example — not a live endpoint

Request
POST https://api.flagship.example/v1/switch/iso8583/forward
Authorization: Bearer $FLAGSHIP_TOKEN
Content-Type: application/octet-stream <ISO8583 binary payload>
Response
{ "trace_id": "sw_9f2a", "mti": "0210", "response_code": "00", "route": "on_us", "latency_ms": null
}

SDKs & client libraries

Host integration packs for common ISO 8583 dialects — scoped at discoveryTMS APIsOperator console

Sandbox

Lab switch + terminal simulators are provisioned with solutions engineering — request sandbox (sales-assisted lab).

Typical integration timeline

  • DiscoveryMessage profiles, BIN ranges, and HSM inventory captured in discovery
  • LabTerminal simulators, velocity policy dry-run
  • Pilot estateLimited MIDs / TIDs for pilot, then staged expansion

Integrations

POS terminalsSchemesAcquirers
07 · Security

Security and compliance

Key material and scheme interfaces are governed with dual control and immutable logs.

HSM-backed PIN/MAC

PIN translation and MAC follow HSM policies agreed at onboarding against your certified HSM list.

Immutable message logs

Routing and response decisions retain trace identifiers for disputes.

Segregation of duties

Policy authors vs approvers for velocity and hotlist changes.

08 · Commercial

Pricing orientation

Switch programmes are typically licensed by estate size and deployment model. Numbers on request.

Terminal count

Active TIDs under TMS.

Peak auth volume

Busy-hour authorization rate you must sustain.

Deployment

On-prem vs private cloud vs hybrid.

Scheme / HSM scope

Interfaces and key ceremonies in scope.

Capacity and commercial sizing happen after a technical discovery — not from a public calculator.

09 · FAQ

FAQ

Deal-killing objections, answered plainly.

Does the switch replace our core?

No. It sits on the card rail side; ledgering stays in core banking or your GL.

Can rules differ by region or BIN?

Yes. Policies can be scoped by geography, BIN ranges, and merchant segments.

How do we test new velocity rules?

Shadow and canary modes reduce blast radius before full promotion.

Can Fraud Engine sit in-line?

Yes. Dual-rail evaluation is designed so CNP gateway and CP switch can share policy vocabulary.

Size the estate in discovery

Bring terminal counts, peak hours, and message profiles. We will map lab next steps with your estate constraints.