> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://support.halocard.co/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How secure is my data when I use Halocard?

We also employ multiple security controls to keep your data safe:

**We do not store user data on our servers**
* Sensitive data collected during onboarding like identity documents are sent and stored exclusively by our verification provider. 
* Virtual card details and transaction history are stored exclusively by our issuing bank. We query this information only when required.
* Payment method details, for example a debit card number used for funding, are entered via PCI-compliant, payment processor iFrames which we do not have access to.

**Two-factor authentication (2FA) is required for all accounts**
* 2FA via Passkey or TOTP is enforced shortly after account opening to prevent unauthorized access via email hijacking, impersonation or social engineering.

**All development follows OWASP Secure Design Principles and is audited annually**
* We follow strict OWASP principles for application development including least privilege, defense in depth, attack surface minimization, secure defaults, et al.
* All traffic is protected in transit using 256bit end-to-end encryption
* Security audit and penetration testing from a certified third party is completed annually
