Generation and tokenisation
PAN creation with atomic sequencing, immediate tokenisation and managed encryption. The real PAN stays inside the secure perimeter for its whole lifecycle; the rest of the issuer stack works on the token.
The secure environment where the PAN lives — and which it never leaves. Optional: it is a prerequisite for no other module.
PAN creation with atomic sequencing, immediate tokenisation and managed encryption. The real PAN stays inside the secure perimeter for its whole lifecycle; the rest of the issuer stack works on the token.
Generation, activation, suspension, reactivation and cancellation, with a state machine and complete trail.
Per-issuer access governance, with individual credentials, limits and metrics, and physical data segregation validated under load.
An environment designed and operated in conformity with PCI-DSS v4.0.1 and PCI-PIN requirements, with privilege segregation and a complete audit trail. The architecture reduces the issuer’s PCI scope.
Validation
Multi-tenancy validated under load: three concurrent issuers at 1,500 TPS, 100% success and p95 latency under 50 ms, with physical per-issuer segregation.
Issuer stack
UNCHANGEDCard core and customer records
Accounts, limits, billing and records stay with the issuer.
Processor / switch
The issuer’s own system keeps authorising the transaction.
Risk & fraud
Fraud tooling stays. We supply the primitive, not the risk decision.
Personalisation bureau
Physical cards keep being produced by the issuer’s bureau.
Portals and channels
The issuer’s app, portal and support are untouched.
Legacy databases
No database migration is required to start.