Security

Security and compliance

Last reviewed

A gift card balance is money you owe your customers. That makes your gift card platform a financial record as much as a marketing tool, and we build it accordingly.

Gift card codes and balances

  • Codes that can't be guessed. We generate every code with enough randomness that an attacker can't work through them in sequence. Predictable codes are how most large-scale gift card losses start.
  • Encrypted at rest, never shown in full. Codes are encrypted rather than stored as plain text, and admin screens and exports only ever show part of one. A compromised staff login or a leaked report doesn't hand anyone spendable value.
  • Rate-limited redemption. We rate limit redemption and balance-check requests, which is what stops someone testing codes against your program at scale.
  • One balance. The balance lives in one place rather than being copied to each channel, so nobody can spend the same value twice by hitting two tills at once.

Account and staff access

  • Separate permissions. Issuing, adjusting a balance and bulk creation are three different permissions, so your till staff can redeem without being able to create value.
  • Two-factor authentication. Required for issuing, adjusting and bulk creation, and available across your whole account.
  • Audit trails. Every issuance, adjustment and redemption records the staff member, the channel and the timestamp.
  • Per-card suspend. Freeze a card from the dashboard and it stops working on every connected channel at once.

Platform and data handling

Your data is stored on Amazon Web Services in the United States. We encrypt it in transit and at rest, run production and test environments separately, scope staff access with two-factor authentication, review security regularly, run due diligence on our vendors, and handle incidents under a defined process. What we collect and how long we keep it is set out in the privacy policy.

Payment data

We never store raw payment card numbers. When a customer buys a gift card, the payment is handled by your POS, your eCommerce checkout, or Stripe on the Wrapped storefront all of which hold PCI DSS Level 1 certification. What we record is the gift card transaction itself: amount, recipient, scheduled delivery, personalised message, redemption history and balance. Card data never reaches us, which keeps it out of scope entirely.

Certification

SOC 2 certification is in progress. The controls described above are built to that standard and already in place. Our infrastructure runs on AWS, which holds SOC 2 and ISO 27001 for the layers it operates, and card payments stay with PCI DSS Level 1 providers. Those certifications cover their layers, not ours, which is why we're pursuing our own.

The fraud these controls stop

Card draining, code harvesting, social engineering, chargeback fraud and internal fraud each exploit a different weakness, and each needs a different control. Our gift card fraud prevention guide works through all five and the defence for each.

Running a security review

Email support@wrappedgiftcards.com and we'll send the current compliance pack, a completed security questionnaire, or a data processing agreement.

The Pro plan and above include a separate test-mode API token, so your developers can validate an integration end to end without touching production data.

Security: frequently asked questions

Is Wrapped SOC 2 or PCI DSS certified?
SOC 2 certification is in progress. In the meantime the controls described on this page (encryption in transit and at rest, role-based permissions with two-factor authentication, full audit trails, separated production and test environments, and defined breach-response procedures) are built to that standard and already in place. On payments: we never store raw card numbers. Card payments are handled by your POS, your eCommerce checkout, or Stripe on the Wrapped storefront, so card data stays with providers holding PCI DSS Level 1 certification. Our infrastructure runs on AWS, which holds SOC 2 and ISO 27001 for the layers it operates. If you're running a formal security review, email support@wrappedgiftcards.com for current documentation and a questionnaire response.
How are gift card codes protected?
Codes are generated with enough randomness that they can't be guessed or worked through in sequence, and they're encrypted at rest rather than stored as plain text. We never show a full code in admin tools or reports. Redemption and balance-check endpoints are rate limited, which is what stops an attacker testing large numbers of codes against your program.
Who at my business can issue or adjust gift cards?
Only the people you authorise. Issuing, adjusting a balance and bulk creation are three separate permissions, so a till user can redeem without being able to create value. Two-factor authentication is required for those higher-privilege actions. Every issuance, adjustment and redemption is written to an audit trail with the staff member, the channel and the timestamp, so you can reconstruct exactly what happened.
What happens if we suspect a card has been compromised?
Suspend it from the dashboard and redemption stops on every connected channel at once, rather than you working through tills one at a time. The card's timeline shows its full redemption history by channel, so you can scope the problem in a single session. Speed matters: the window between a code being harvested and the balance being drained is usually short.
Where is our data stored, and what happens to it if we leave?
Your data is stored on Amazon Web Services in the United States. Full detail on handling and retention is in our privacy policy. If you cancel, you can export the complete gift card ledger (codes, balances and transaction history) within 30 days. Outstanding balances stay redeemable obligations to your customers under applicable consumer protection law.
Do you have access to our customers’ payment details?
No. Payment processing stays with your existing provider: your POS, your eCommerce checkout, or Stripe on the Wrapped storefront. We record the gift card transaction itself: amount, recipient, delivery, redemption history and balance. Never the card used to pay for it.

Get started to turn gift cards into your biggest revenue stream