Skip to content
MILETIA
Menu

Your platform stays. The cryptography connects into it.

EMV, NFC and CDE for closed-loop schemes.

MILETIA delivers payment cryptographic infrastructure as a service, deployed in the client’s own cloud environment. The issuer keeps its systems, databases and operation, and connects the modules it needs to the stack it already runs.

EMVOPTIONAL· Key derivation· ARQC validation· ARPC generation· CVV / PVVNFCREQUIRES EMV· DPAN & TSP· Provisioning· Device tokens· ManagementCDEOPTIONAL· PAN generation· Tokenisation· Data vault· Audit

Interconnect panel

The issuer stack is not replaced.

Connect the modules to see the rule.

Issuer stack

UNCHANGED
  • Card core and customer records

    Accounts, limits, billing and records stay with the issuer.

  • Processor / switch

    The issuer’s own system keeps authorising the transaction.

  • Risk & fraud

    Fraud tooling stays. We supply the primitive, not the risk decision.

  • Personalisation bureau

    Physical cards keep being produced by the issuer’s bureau.

  • Portals and channels

    The issuer’s app, portal and support are untouched.

  • Legacy databases

    No database migration is required to start.

Exactly one requirement

EMV and CDE can each be contracted on their own. NFC requires EMV, because device tokenisation depends on keys derived at the chip. This is not a commercial bundle — it is a technical prerequisite.

EMVSTANDALONE
CDESTANDALONE
NFCREQUIRES EMV

Adoption journey

Entry with minimal change; expansion by configuration.

01Entry

The issuer replaces its Data Preparation and cryptographic management supplier, keeping its current bureau, authoriser and operation. Immediate value, minimal change.

02Expansion

Contactless payment activated with the issuer’s own SDK and wallet, under its own application identity.

03Evolution

Integration with market digital wallets and open-loop support via the schemes’ tokenisation providers — planned evolution of the platform.

What already stands

Verifiable facts, each with its real status.

Own issuer identity

Registered

A000000976

MILETIA operates under its own registered RID — a category A application provider identifier, ISO/IEC 7816-5, registered 2026-08-04. It is the basis for proprietary AIDs and independence from third-party identities.

Validated in real production

Validated

Market capture terminals

Cards personalised by the platform transacted with approval on market capture terminals, in the real acquirer authorisation flow.

Certified payment HSM

In use

FIPS 140-2 Level 3

Every key and PIN operation runs entirely inside certified payment HSMs, with TR-31 key blocks, dual control and split knowledge in key ceremonies. Available on AWS and Azure, matching the client environment.

Multi-tenancy under load

Measured

1,500 TPS · p95 < 50 ms

Three concurrent issuers at 1,500 transactions per second, 100% success, with physical per-issuer database segregation validated during the run.

In-house NFC tokenisation

Available

DPAN · device keys · cryptogram

Digital credential provisioning on mobile devices with an in-house token service for closed-loop schemes, integrable with the issuer’s own digital wallet via SDK. Full token lifecycle.

Security and compliance

Operated in conformity

PCI-DSS v4.0.1 · PCI-PIN

The CaaS is designed and operated in conformity with PCI-DSS v4.0.1 and PCI-PIN requirements. The architecture reduces the issuer’s PCI scope: sensitive data stays concentrated in the service perimeter, and client systems interact through APIs that dispense contact with the real data.

Talk to MILETIA

A technical evaluation of your environment and a deployment proposal. For the engineering team, the technology page shows how the service is deployed and consumed by API.

Identification

RID
A000000976
Registered
2026-08-04
Category
A — ISO/IEC 7816-5
Cloud
AWS · Azure — client tenant
Certification
FIPS 140-2 L3 · PCI HSM v3