CardBridge Get a card
Security

What we do with the data, in specifics.

If we are going to be the thing that vouches for your staff, you are entitled to know exactly how it is built and where it runs.

How it is built and where it runs

Residency

Sydney, by default

Primary database, object storage and backups run in Sydney (ap-southeast-2). Australian customer data stays onshore unless you ask otherwise.

In transit

TLS 1.2+ everywhere

HSTS enforced, no mixed content, modern cipher suites only. Verification pages are served over HTTPS on your own hostname.

At rest

Encrypted volumes

Database and object storage encrypted at rest. Passwords are not stored at all — sign-in is a single-use emailed link.

Access

Least privilege, logged

Production access is limited to staff who need it, requires a second factor, and writes an entry you can request.

Tenancy

Scoped at the query layer

Every read is filtered by organisation in one shared data layer rather than per endpoint, so a missed check in a new feature cannot leak across customers.

Privacy by design

No visitor tracking

Verification and profile pages set no cookies and record no IP addresses. We store a coarse country and nothing that identifies the person who tapped.

Commitments

Things we will put in writing

  • Revocation speed. A revoke propagates to the public page within 60 seconds. It is a cache TTL, not a queue that might be backed up.
  • Breach notification. We follow the Notifiable Data Breaches scheme: affected people and the OAIC are notified as soon as practicable where serious harm is likely.
  • Export on demand. Your profiles, cards and captured contacts export to CSV and JSON at any time, including after you cancel.
  • Deletion on request. Account data is deleted 90 days after closure. Ask for it sooner and we do it sooner.
  • Subprocessor changes. Team and Verified customers are told before we add a supplier that touches personal information.
  • No data sale, ever. Not aggregated, not anonymised, not as a footnote in the terms. Contact data is the one asset a customer trusts us with.

What we do not have yet

No SOC 2 report and no ISO 27001 certificate. Both cost more than this business currently makes, and claiming them would be worse than admitting it. If your procurement process requires one, tell us — it changes what we prioritise, and we would rather hear it than guess.

Security questions and disclosure reports go to security@getcardbridge.com. We reply within one business day and we do not threaten researchers.

Get started

Try it on one colleague first.

The 14-day trial takes about four minutes to set up and needs no card details. Order the printed card once you like the page it opens.