Skip to content
ACTTRAQ

Security & compliance

Built for the institutions that carry the risk.

Banks do not adopt infrastructure that widens their exposure. The architecture is designed so that participating in a shared intelligence layer never means sharing your cardholders.

Principles

Four architectural commitments.

  • Tokenized by default

    Sensitive card data is tokenized and encrypted in a dedicated vault. The platform operates on tokens and de-identified attributes, not on raw pans.

  • Issuer isolation

    No issuer's data is exposed to another issuer. Cross-institution learning runs on aggregated, de-identified signals; each bank's own data, outputs and reporting remain its own.

  • Non-intrusive by design

    ActtraQ observes and acts alongside the authorization flow. It is not in the approval path — nothing the platform does can decline, delay or alter a payment.

  • Auditable end to end

    Enrolment, offer assignment, delivery and settlement are individually auditable, so campaign outcomes and the money attached to them can be reconciled after the fact.

Infrastructure

Where it runs.

The platform runs on Microsoft Azure, with PCI DSS controls applied to the components in scope and a dedicated token vault isolating cardholder data from the rest of the system.

  • Microsoft Azure infrastructure
  • PCI DSS controls on in-scope components
  • Dedicated token vault for cardholder data
  • Regional deployment options for data residency requirements

Send us your security questionnaire.

We would rather answer it early than late in a procurement cycle.