Products

LinQ1Zero LinQView ScanLinQ Private APN Tier 1 Carrier Network

Solutions

POS & Payments Self-Serve Kiosks Telematics & Fleet Fixed Wireless

Resources

Insights Case Studies Newsroom eNewsletter

Company

About NuvoLinQ Contact Us
Talk to Sales →

Your payment data never touches a public network.

Every NuvoLinQ connection runs on a dedicated private APN: a network lane used exclusively by your devices. Cardholder data travels a controlled, isolated path from the terminal to your payment processor, never across the public internet.

Destination laneNo public
network exposure
Fixed addressStatic IP on
every device
Not an add-onIncluded as
standard

01Plain-language explanation

What a private APN is, and why it matters for payments.

APN stands for Access Point Name. It's the gateway that decides which network your device connects to when it sends data. A private APN means that gateway is yours alone: no other company's devices use it.

01

A dedicated network lane

On a shared public APN, your terminal's data travels alongside every other IoT device on that carrier. A private APN creates a separate, isolated path used only by devices you control. Nothing else gets in.

Public APN — shared with all devicesOPEN
NuvoLinQ Private APN — your devices onlyPRIVATE
02

Static IP is a fixed, routable address

Every device gets a fixed IP address that never changes. That makes IP whitelisting possible: your firewall accepts connections only from your terminal IPs and blocks everything else.

DeviceAssigned IP
Terminal · Toronto10.44.22.18
Terminal · Calgary10.44.22.31
03

Full data sovereignty

Your payment data travels from terminal to processor on a controlled path only. It is never routed through uncontrolled networks or unknown intermediaries along the way.

TerminalPrivate APNProcessor

02The compliance risk

Why a public APN creates a compliance gap in your PCI DSS scope.

PCI DSS requires that cardholder data environments be protected from untrusted networks. A public APN puts payment data on shared infrastructure, which is, by definition, untrusted.

⚠ Generic IoT SIM · Shared APN

Cardholder data on a road shared with everyone.

Data travels over public carrier infrastructure alongside untrusted IoT traffic from other organizations.
Dynamic IP addresses make IP whitelisting impossible — you cannot restrict which organizations connect to your payment infrastructure.
No control over data routing — traffic may traverse unexpected geographic regions.
Shared APN connections expand your cardholder data environment, increasing PCI DSS scope and audit effort.
No mechanism to implement PCI DSS Requirement 1.4 network access controls between your terminal network and untrusted networks.
✓ NuvoLinQ Private APN

A controlled, auditable path your compliance team can document.

All payment data travels exclusively through your private APN, never shared with any other organization's traffic.
A static IP on every device enables complete IP whitelisting, so your firewall accepts connections only from your specific terminal addresses.
Data sovereignty maintained throughout, traffic stays within defined geographic boundaries from terminal to processor.
Supports PCI DSS scope reduction, auditors can verify that cardholder data travels on a controlled, isolated network segment.
Every connection event logged and exportable, full audit trail available for Requirement 10 log management.

03How it works

How NuvoLinQ's private APN works in practice.

Three components work together to give you isolated, controlled, and auditable connectivity for every terminal in your fleet.

Step 01

Dedicated private APN

When your LinQ1Zero SIM connects, it routes exclusively to NuvoLinQ's private APN, never to the shared public carrier. No configuration required on your side. The private APN is already live.

Step 02

Static IP assignment

Each device is assigned a fixed IP at provisioning. That address never changes, not between sessions, not after carrier switches, not after reboots. This makes IP whitelisting stable and permanent.

Step 03

PCI DSS scope support

A private APN isolates your cardholder data environment from untrusted networks, satisfying PCI DSS Requirement 1 and supporting scope reduction so your QSA can exclude the rest of your network from assessment. Every connection is logged and exportable for your audit.

04Static IP, specifically

Every device gets a fixed, routable IP address.

A static IP isn't just a technical detail. It's what makes IP whitelisting possible, keeps remote management reliable, and lets firewall rules hold.

Fleet IP assignmentSTATIC · NEVER CHANGES
DeviceLocationIP address
Terminal #4821Toronto10.44.22.18
Terminal #2934Calgary10.44.22.31
Terminal #1102Vancouver10.44.22.45
Terminal #8834Montréal10.44.22.59

IP whitelisting

Configure your firewall to accept connections only from your fleet's IP range and block everything else. Because the IPs never change, the rules never break, no matter how many times the device reconnects or switches carriers.

Remote management

Your LinQView dashboard and operations team always know the exact address of every device. Remote configuration, diagnostics, and OTA updates are reliable because the device is always reachable at the same address.

Firewall rules that hold

A static IP survives carrier switches and reboots. When a terminal drops and reconnects, it comes back on the same IP, your firewall rules and your compliance documentation stay valid.

Assigned at provisioning. Static IP is configured when your SIM is provisioned before it ships. No setup required on your end. Every device in your fleet arrives with a fixed address already assigned.

05For POS specifically

What private APN & static IP mean for your payment fleet.

Four things that change for a payment operations or compliance team when every terminal runs on a private APN with a static IP address.

Cardholder data protection

Card data never touches a public network

From the moment cardholder data leaves the terminal to the moment it reaches your acquirer, it travels exclusively on NuvoLinQ's private APN. At no point in that journey does it cross the public internet or a shared carrier APN.

Access control

A whitelist you set once

Because every device keeps the same IP for life, you whitelist your fleet once and leave it. Reconnects, reboots, and carrier switches all return on the same address, so your rules and your audit evidence never go stale.

PCI DSS audit readiness

A documented answer for your QSA

A private APN is a documented, auditable network control. When your QSA asks how cardholder data is isolated in transit, "private APN with static IP whitelisting" answers the question. A shared carrier APN does not.

Geographic data routing

Data stays within defined geographic boundaries

NuvoLinQ's private APN keeps traffic within defined geographic regions. Payment data from a Canadian terminal does not route through an overseas peering point on its way to a Canadian processor.

06Not an add-on

Included with every NuvoLinQ connection. No upgrade required.

Private APN and static IP are not premium tiers or optional features. Every LinQ1Zero SIM on every NuvoLinQ plan runs on the private APN with a static IP address assigned at provisioning.

"

Most IoT connectivity providers charge extra for private APN access, if they offer it at all. At NuvoLinQ, it's the default. We built the network this way because payment terminals have no business running on shared infrastructure. Every connection we provision is a private one.

Private APN — included on every plan · No upgrade required
Static IP — assigned at provisioning · Fixed for life of deployment
Data sovereignty — traffic stays within defined geographic boundaries
Connection logging — every event logged and exportable for PCI audit

07How it compares

NuvoLinQ private APN vs shared public APN from generic IoT SIM providers.

For payment infrastructure, the difference between a private and a public APN is the difference between a defensible PCI DSS architecture and one your auditor will flag.

Capability
Shared public APN · Generic IoT SIM
NuvoLinQ · Private APN
Network isolation
Shared with every device on the carrier
Dedicated lane for your devices only
IP address type
Dynamic, changes every session
Static, fixed at provisioning, never changes
IP whitelisting
Not possible with dynamic IPs
Fully supported, whitelist your exact terminal IPs
Firewall rule stability
Rules break when IPs change
Rules persist, static IP survives carrier switches
Data sovereignty
Routing path varies and may cross unexpected regions
Defined geographic boundaries controlled throughout
PCI DSS Req. 1 support
Shared APN treated as untrusted — expands scope
Private APN supports documented network segmentation
Connection audit logs
Limited or not available for compliance export
Full log: timestamp, device, IP, carrier
Cost
Often a premium add-on if available at all
Included as standard, every plan, every connection

08 · Get a connectivity review

See how your current connectivity compares, before your next PCI audit does.

Our team will review your existing SIM connectivity setup against PCI DSS requirements and show you exactly where a private APN closes the gaps. No obligation, just a clear picture of where you stand.

Connectivity assessment
Review your current SIM setup vs PCI DSS
PCI DSS connectivity guide
How a private APN supports your compliance architecture
Talk to a network engineer
30-min call · APN setup, IP assignment, firewall rules