1. Our approach
EasyCards maintains administrative, technical, and organizational measures designed to protect the confidentiality, integrity, and availability of the services and data we handle.
We evaluate controls based on data sensitivity, service design, relevant threats, contractual commitments, legal requirements, and the responsibilities of issuing, banking, processing, network, and other program partners.
2. Infrastructure and network protection
Public EasyCards web properties and supported service endpoints use encrypted HTTPS connections. We use managed infrastructure and edge security services to support traffic protection, availability, and secure delivery.
Production environments are logically separated from development workflows. Network exposure and administrative access are limited according to operational need and service architecture.
3. Data protection
Controls are designed to support:
- encryption in transit for supported connections;
- protection of stored sensitive data using platform and application controls appropriate to the service;
- data minimization, purpose limitation, and retention practices;
- handling of credentials and secrets outside public source code; and
- restricted access to cardholder, transaction, onboarding, and compliance information.
Customers should avoid sending passwords, complete payment credentials, private keys, or other highly sensitive information through ordinary email or support messages.
4. Identity and access management
Access controls are designed around least privilege, role separation, authentication, and review of privileged access. Access is granted according to job responsibilities and service needs and should be removed when no longer required.
Customer administrators are responsible for managing their own users, API keys, permissions, approval policies, and devices. Available authentication or access features depend on the contracted service.
5. Secure development and change management
Our development practices are designed to include code review, dependency management, controlled deployment, testing, and remediation of identified security issues in proportion to risk. Material changes are evaluated before production release.
We review exposed services and dependencies for known weaknesses and prioritize remediation based on severity, exploitability, exposure, and potential impact.
6. Logging, monitoring, and incident response
EasyCards maintains logging and monitoring appropriate to the relevant service to support operational visibility, security investigation, and detection of suspicious activity.
Incident response processes are designed to support triage, containment, investigation, recovery, and required notification. Customers should maintain accurate security contacts so we can coordinate when an event affects their program.
7. Resilience and continuity
Service architectures and operational processes are designed with availability and recoverability in mind. Specific uptime, recovery, backup, and support commitments apply only when stated in a signed service agreement.
Some availability events depend on card networks, issuers, banks, processors, cloud providers, or other systems outside EasyCards’ direct control.
8. Service providers and program partners
EasyCards may use service providers and program partners for hosting, communications, identity verification, compliance, risk, processing, issuing, funding, and other functions. We evaluate relevant security and data protection considerations when selecting and managing these relationships.
Partners maintain their own controls and may provide separate security, privacy, and compliance documentation.
9. Customer security responsibilities
Customers and authorized users should:
- protect account credentials, API keys, devices, and recovery methods;
- use least-privilege roles and promptly remove unnecessary access;
- configure transaction limits, merchant controls, approvals, and alerts appropriate to their risk;
- validate webhook signatures or other available authenticity controls;
- monitor program activity and report suspected misuse promptly;
- secure their own applications, endpoints, integrations, and cardholder communications; and
- comply with program documents, network rules, privacy law, and applicable security requirements.
10. Compliance and certification statements
EasyCards does not claim a certification, attestation, regulatory status, or compliance scope on this page. Any representation regarding PCI DSS, SOC, ISO, regulatory licensing, or another formal standard is valid only when confirmed in current written documentation supplied for the applicable service or program.
A card program may also rely on the compliance programs of its licensed issuer, processor, bank, network, or other partner.
11. Report a security issue
If you believe you found a vulnerability or security issue, send a concise description, affected URL or service, and safe reproduction details. Do not access other users’ data, disrupt services, or include secrets or full payment credentials.
Security reports: support@easycards.io
Use the subject line Security Report. We do not currently promise a public bug bounty or payment unless agreed in writing before testing.