Security Overview

Your Security is Our Priority

CardFi is built from the ground up with security at the core. Here's everything we do to protect your account and funds.

End-to-End Encryption
All data transmitted between your device and CardFi servers is encrypted using TLS 1.3. Sensitive data is encrypted at rest using AES-256.
Email OTP Verification
Every login requires a one-time 6-digit code sent to your registered email. No access is granted without this second factor.
PIN Protection
A personal 6-digit PIN secures your account session. PINs are hashed and never stored in plain text. Wrong PIN attempts trigger account lockout.
Recovery Phrase
A 12-word recovery phrase is generated at signup. This is your ultimate account recovery method. We never store it — only you have it.
Fraud Detection
Real-time transaction monitoring detects unusual patterns, suspicious addresses, and potential fraud — automatically freezing at-risk activity.
Card Controls
Freeze and unfreeze your virtual card instantly from the dashboard. Set spending limits. Reveal CVV only when needed, with time expiry.
Security Technologies We Use
TLS 1.3
Latest transport layer security for all data in transit
AES-256 Encryption
Military-grade encryption for sensitive data at rest
Time-Based OTP
6-digit codes expire within 10 minutes for login security
bcrypt Password Hashing
Passwords are never stored in plain text — always salted and hashed
Rate Limiting
Brute force protection on all authentication endpoints
How to Keep Your Account Safe

Found a Security Vulnerability?

We take security reports seriously. If you've discovered a potential vulnerability in CardFi, please report it responsibly. We'll investigate and respond within 48 hours.

Responsible Disclosure →