Security & compliance

Security first.
By design.

Built for banks from day one: the least card data possible, encrypted everywhere, and every action on the record.

A cardoff.ai card held in hand
Never a full card number
Scope-light by design

We never see the full card number.

Linking a card takes the first 5 and last 4 digits and a one-time code to the bank's registered mobile. The middle digits never leave the cardholder.

45871•••••••1047+ OTP
What we useNever collectedOne-time code to the bank's mobile

Controls your auditors
will recognise.

Built to the standards banks work with, and documented so your risk team can check.

PCI DSS, scope-light

Designed so full card numbers never enter the platform, keeping your PCI scope as small as possible.

  • First 5 + last 4 + OTP token only
  • Card files checked: full numbers are rejected
  • Built to align with PCI DSS v4.0

SOC 2 aligned

Security, availability and confidentiality controls modelled on the SOC 2 trust criteria.

  • Change management with approvals
  • Monitoring and incident response
  • Vendor and access reviews

ISO 27001 aligned

An information security management system built along ISO 27001 lines.

  • Risk register and treatment
  • Documented policies
  • Regular internal reviews

Encrypted everywhere

Data is encrypted in transit and at rest, and sensitive fields are encrypted per bank.

  • TLS for every connection
  • Encryption at rest
  • Mobile numbers matched by keyed hash

Full audit trail

Every change is recorded: who asked, who approved and what happened, including everything Hyduri does.

  • Immutable action log
  • AI actions need approval
  • Exportable for audits

Roles and maker-checker

Fine-grained roles per team, and a second person to approve anything that matters.

  • Role-based access control
  • Maker-checker approvals
  • Per-bank data isolation

Single sign-on

Your staff sign in with your identity provider, and leavers lose access the moment you remove them.

  • SAML and OpenID Connect
  • Multi-factor sign-in
  • Session controls

Privacy by default

Merchants see redemption statistics, never your cardholders' personal data.

  • No cardholder data shared with merchants
  • Pseudonymous identifiers for tracked links
  • Built for Bahrain's PDPL

Your data, where it belongs.

Hosted in Bahrain by default, with regional cells when your regulator needs data kept in-country.

BahrainDefault region for the platform
Regional cellsIn-country hosting where regulation requires it
Dedicated regionYour own isolated environment on Enterprise

cardoff.ai is built to align with PCI DSS, SOC 2 and ISO 27001. Ask us for our current attestation status and security documentation, shared under NDA.

cardoff.ai billboard in the city

Let's build a more rewarding tomorrow.