Security

Security at
Every Layer

Security is foundational to CardPing — not an afterthought. Here's how we protect your data and your customers' cards.

🛡️

PCI DSS Level 1

Highest level of PCI compliance. Annual QSA audit.

📋

SOC 2 Type II

Security, availability & confidentiality independently audited.

🌐

ISO 27001

International standard for information security management.

🔒

TLS 1.3 Only

All API traffic encrypted. No legacy protocol support.

🇪🇺

GDPR Compliant

Full GDPR compliance. DPA available for EU customers.

⚔️

Annual Pen Test

External penetration testing by specialist security firm.

🔍 Responsible Disclosure

Found a security vulnerability? Report it to security@cardping.io. We run a bug bounty programme and acknowledge all valid reports within 24 hours. Please allow 90 days before public disclosure.

Contact Security Team →