D-Card
Security at D-Card
Last updated: 2026-08-18 This Trust page describes security practices D-Card uses when operating D-Card. It is not a warranty, certification, or insurance policy. We do not claim SOC 2, ISO 27001, PCI DSS, HIPAA, "bank-grade," or end-to-end encryption of all user content unless independently verified and expressly stated after review.
1. Our Approach
Security is part of how we build and run accounts, digital cards, public sharing, Admin tools, and APIs. We combine preventive controls, monitoring, and response processes appropriate to a professional networking SaaS of our scale.
2. Controls We Aim to Maintain
Depending on environment configuration, measures include:
Transport security
- HTTPS/TLS for API and web traffic in deployed environments
Authentication and sessions
- Hashed password storage
- Session-based authentication with revocation on logout, security events, and account deletion approval
- Optional biometric unlock convenience on supported devices (device-local)
Authorization
- Role-based access control for Admin operations
- Permission checks on administrative actions
Application safeguards
- Input validation and rate limiting on sensitive endpoints
- Separation of public card payloads from private account credentials
- Secure handling of OTP / verification flows
Operations
- Restricted production access for operators
- Logging of security-relevant Admin and auth events where implemented
- Backups according to environment operations (retention is an operational decision)
Notifications and email
- Transactional email via configured providers (for example Brevo when enabled) for security-related notices
- Push token management with revocation on account deletion approval
3. Public Cards and Shared Links
A public card URL or QR code is designed to be viewable without login. Treat anything you place on a public card as public. Security of a shared link also depends on how widely you distribute it.
4. Your Responsibilities
- Use strong unique passwords and protect your devices
- Review public fields before sharing
- Keep the app updated
- Report suspicious account activity promptly
5. Vulnerability Reporting
If you believe you have found a security vulnerability in D-Card, please email security@d-card.io with enough detail to reproduce the issue. Please:
- Do not access data that is not yours
- Do not degrade the Service
- Allow reasonable time for investigation before public disclosure
We appreciate good-faith research. This page does not create a paid bug bounty unless we separately announce one.
6. Incident Communication
If a personal-data incident requires notice under applicable law, we will provide notifications consistent with legal requirements and our Privacy Policy.
7. Related Documents
8. Contact
- Security: security@d-card.io
- Support: support@d-card.io
- Privacy: privacy@d-card.io
- Entity: D-Card · Registered office details available on request at support@d-card.io
- Website: https://d-card.io