Cardvera sits between your customers and your payment stack. That position demands a security posture we're willing to publish. This page covers what we do and how to reach us when you find something.
The safest data is data we never see. Every architectural decision starts from that principle.
Cardvera doesn't touch cardholder data. The browser SDK never reads card fields, and card numbers, CVVs, and expiry dates never pass through our systems — we classify on behavior and network telemetry. Transaction outcomes reported through the Outcome API need no cardholder data; a BIN, which isn't sensitive, is optional. Full card data stays between the cardholder and your gateway, and your PCI scope is unchanged.
Every connection is encrypted with TLS — browser to edge, edge to your backend, internal service to service. No unencrypted channels.
Your signals, verdicts, and transaction data stay in your own tenant and are never shared with other customers. Verdicts are signed server-side, so they can't be spoofed or tampered with from the browser.
SOC 2 is on our roadmap, and readiness work is underway now: controls covering security, availability, and confidentiality are being built in from the start. We'll share the report with customers once it's issued.
We store behavioral signals and session metadata — no card data, names, or email addresses. Collected signals are retained only as long as operationally necessary. Verdicts are single-use; session tokens expire after each checkout flow.
We use a small, fixed list of infrastructure subprocessors. The current list is available on request. We review and re-assess subprocessors when their role changes or annually, whichever comes first.
The Cardvera SDK collects browser environment signals (runtime properties, timing, motion telemetry) and network metadata (IP, ASN, user-agent) for the purpose of producing a fraud verdict. These signals are summarized locally and transmitted to our edge over TLS. We do not collect, store, or process payment card numbers, CVV codes, full names, email addresses, or any other information that identifies a cardholder.
Collected signals are associated with a short-lived session token and a merchant tenant identifier. They are never shared with other customers, never sold to third parties, and used only for fraud classification.
What we do share is protection. When we see an attack on one merchant, the block rules built from it are deployed to protect every merchant on Cardvera. Those rules describe the attacker — fingerprints of the clients, networks, and patterns involved — never merchant or customer data.
We process data in the United States. We're happy to sign a Data Processing Agreement — just ask.
We welcome good-faith security research. If you've found a vulnerability in Cardvera's systems, we want to hear about it before it becomes a problem for our customers.
Email a description of the issue, steps to reproduce, and any supporting evidence to security@cardvera.io. You can also find our machine-readable policy at /.well-known/security.txt.
A clear description of the vulnerability and its potential impact; reproduction steps or a proof-of-concept; the affected URL, endpoint, or component; your contact details for follow-up.
We will acknowledge receipt within two business days, keep you informed as we investigate, and notify you when the issue is resolved. We aim to triage critical reports within five business days.
We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, avoid accessing or modifying customer data, do not perform denial-of-service attacks, and report findings to us before public disclosure.
Please do not test against merchant accounts you do not own or have explicit written permission to test. Automated scanning at scale against our production edge is not permitted under this policy.
We do not currently operate a paid bug bounty program, but we publicly acknowledge responsible disclosures (with the researcher's permission) and are grateful for the effort good-faith research requires.
Contact: security@cardvera.io