Articles on: 🔒 Privacy & Security

How secure is my data when I use Halocard?

We also employ multiple security controls to keep your data safe:


We do not store user data on our servers

  • Sensitive data collected during onboarding like identity documents are sent and stored exclusively by our verification provider.
  • Virtual card details and transaction history are stored exclusively by our issuing bank. We query this information only when required.
  • Payment method details, for example a debit card number used for funding, are entered via PCI-compliant, payment processor iFrames which we do not have access to.


Two-factor authentication (2FA) is required for all accounts

  • 2FA via Passkey or TOTP is enforced shortly after account opening to prevent unauthorized access via email hijacking, impersonation or social engineering.


All development follows OWASP Secure Design Principles and is audited annually

  • We follow strict OWASP principles for application development including least privilege, defense in depth, attack surface minimization, secure defaults, et al.
  • All traffic is protected in transit using 256bit end-to-end encryption
  • Security audit and penetration testing from a certified third party is completed annually

Updated on: 17/07/2026