Defense in Depth
Multiple layers of controls protect every aspect of our infrastructure—from network perimeters to application code and data storage.
eWallet's security program blends modern infrastructure, rigorous processes, and constant monitoring. This policy summarizes the controls we maintain to protect customers, partners, and the broader ecosystem.
Need more detail or want to report an issue? Reach our security team.
eWallet operates within a security ecosystem maintained by our certified partners. While eWallet itself does not hold PCI DSS, SOC 2, or ISO 27001 certifications, we partner with certified service providers and align our internal controls with industry standards. Card data is processed by PCI DSS-certified partners, our systems are hosted in SOC 2-certified data centers, and our security controls align with ISO 27001 standards.
These principles guide decision making across engineering, operations, and risk.
Multiple layers of controls protect every aspect of our infrastructure—from network perimeters to application code and data storage.
Employees and systems receive only the permissions required to perform their jobs, reviewed regularly with automated tooling.
We instrument logs, metrics, and anomaly detection across our platform and enforce 24/7 response protocols.
Layered controls protect infrastructure, applications, data, and access.
We partner with industry-leading service providers who maintain relevant security certifications.
Card funding & tokenization
Hosting infrastructure
Custodial banking
Card issuer
Our security posture is supported by partner certifications and regulatory oversight.
Card funding, tokenization, and payment processing occur within PCI DSS-compliant environments provided by our certified partners including Stripe.
Our production systems operate in SOC 2-certified data centers provided by Vultr, with enforced encryption and audited access controls.
Our security controls align with ISO 27001 standards, and several of our service providers hold ISO 27001 certifications.
Compliance with BSA/AML, OFAC sanctions requirements, and applicable state/federal privacy regulations.
We employ strong encryption to protect data at rest and in transit.
All data transmitted between your device and our servers is encrypted using TLS 1.3, the latest transport layer security protocol.
Sensitive data stored in our systems is encrypted using AES-256 encryption, the industry standard for data protection.
We do not store raw card numbers. Card details are tokenized and stored by our PCI DSS-certified payment partners.
We value the security community. If you believe you have discovered a vulnerability, let us know at security@ewallet.app. We will work quickly to remediate issues and credit researchers when appropriate.