Investor Demo Mode
· Sandbox environment · All data is simulated · No real funds or cardsCompliance
Regulatory posture · PCI · BSA · Privacy
13/16 Controls Compliant
Last reviewed: March 2026
PCI DSS Level
1
SAQ-D · Audited Jan 2026
SOC 2 Type
I
Type II in progress Q2 2026
Card Network
(3 controls)PCI DSS Level 1
Annual SAQ-D attestation. Last audit: Jan 2026.
Visa/MC BIN Sponsorship
BIN ranges licensed under Coastal Community Bank.
Network Tokenization
TSP token flow certified for Apple Pay provisioning.
Banking & Regulatory
(4 controls)Bank Secrecy Act (BSA)
AML/KYC program in place. SAR filing threshold monitored.
Reg E (Electronic Funds)
Error resolution procedures documented and implemented.
Reg Z (Truth in Lending)
Applicable to credit programs. Credit partner bears obligation.
UDAAP Review
Annual review in progress with external counsel.
Data & Privacy
(5 controls)SOC 2 Type II
Audit scheduled for Q2 2026. Type I complete.
CCPA Compliance
Data mapping complete. DPA templates in place.
GDPR (if applicable)
EU data not processed. Standard contractual clauses ready.
Encryption at Rest
AES-256. PAN data encrypted. CVV never stored at rest.
Encryption in Transit
TLS 1.3 enforced. HSTS enabled. Certificate pinning.
Operational
(4 controls)Vendor Due Diligence
Lithic, Sardine, Pagaya all SOC 2 Type II certified.
Incident Response Plan
48-hour RTO. Runbooks documented. Tabletop completed.
Business Continuity (BCP)
Annual BCP test scheduled for Q3 2026.
Penetration Testing
Annual external pentest. Last: Feb 2026. No criticals.
Compliance Disclosure
ShipCard operates as a technology vendor to fintech programs. Regulatory obligations (Reg E, Reg Z, BSA) are borne by the sponsoring bank and program manager. ShipCard provides technical infrastructure only and does not hold banking licenses, issue credit, or hold deposits. Compliance items marked “In Review” are advisory controls that do not create regulatory exposure for ShipCard or its customers as of the current date. This matrix is for internal tracking and investor due diligence purposes only.