Security first.
By design.
Built for banks from day one: the least card data possible, encrypted everywhere, and every action on the record.
We never see the full card number.
Linking a card takes the first 5 and last 4 digits and a one-time code to the bank's registered mobile. The middle digits never leave the cardholder.
Controls your auditors
will recognise.
Built to the standards banks work with, and documented so your risk team can check.
PCI DSS, scope-light
Designed so full card numbers never enter the platform, keeping your PCI scope as small as possible.
- First 5 + last 4 + OTP token only
- Card files checked: full numbers are rejected
- Built to align with PCI DSS v4.0
SOC 2 aligned
Security, availability and confidentiality controls modelled on the SOC 2 trust criteria.
- Change management with approvals
- Monitoring and incident response
- Vendor and access reviews
ISO 27001 aligned
An information security management system built along ISO 27001 lines.
- Risk register and treatment
- Documented policies
- Regular internal reviews
Encrypted everywhere
Data is encrypted in transit and at rest, and sensitive fields are encrypted per bank.
- TLS for every connection
- Encryption at rest
- Mobile numbers matched by keyed hash
Full audit trail
Every change is recorded: who asked, who approved and what happened, including everything Hyduri does.
- Immutable action log
- AI actions need approval
- Exportable for audits
Roles and maker-checker
Fine-grained roles per team, and a second person to approve anything that matters.
- Role-based access control
- Maker-checker approvals
- Per-bank data isolation
Single sign-on
Your staff sign in with your identity provider, and leavers lose access the moment you remove them.
- SAML and OpenID Connect
- Multi-factor sign-in
- Session controls
Privacy by default
Merchants see redemption statistics, never your cardholders' personal data.
- No cardholder data shared with merchants
- Pseudonymous identifiers for tracked links
- Built for Bahrain's PDPL
Your data, where it belongs.
Hosted in Bahrain by default, with regional cells when your regulator needs data kept in-country.
cardoff.ai is built to align with PCI DSS, SOC 2 and ISO 27001. Ask us for our current attestation status and security documentation, shared under NDA.

