Security & compliance
Built for the institutions that carry the risk.
Banks do not adopt infrastructure that widens their exposure. The architecture is designed so that participating in a shared intelligence layer never means sharing your cardholders.
Principles
Four architectural commitments.
Tokenized by default
Sensitive card data is tokenized and encrypted in a dedicated vault. The platform operates on tokens and de-identified attributes, not on raw pans.
Issuer isolation
No issuer's data is exposed to another issuer. Cross-institution learning runs on aggregated, de-identified signals; each bank's own data, outputs and reporting remain its own.
Non-intrusive by design
ActtraQ observes and acts alongside the authorization flow. It is not in the approval path — nothing the platform does can decline, delay or alter a payment.
Auditable end to end
Enrolment, offer assignment, delivery and settlement are individually auditable, so campaign outcomes and the money attached to them can be reconciled after the fact.
Infrastructure
Where it runs.
The platform runs on Microsoft Azure, with PCI DSS controls applied to the components in scope and a dedicated token vault isolating cardholder data from the rest of the system.
- Microsoft Azure infrastructure
- PCI DSS controls on in-scope components
- Dedicated token vault for cardholder data
- Regional deployment options for data residency requirements
Send us your security questionnaire.
We would rather answer it early than late in a procurement cycle.
