Security

How we protect a card and an account

Two things are worth guarding here: the card codes you hand us, and the door to your account. Here's how each is locked.

Last updated 2026-06-26

Card codes are encrypted at rest

Every card code is encrypted before it's stored, with its own key. We keep it only until the card is fully drawn down, then purge it. It is never written to a log, never shown in the dashboard, and never put in an email.

Who can read a card code

A stored code never shows in your dashboard, in a log, or in an email. The plaintext is read in only three places, and every read is recorded: when you submit a card, to derive a one-way fingerprint that blocks duplicates and fraud; when the system checks the card's balance with the issuer; and, when a conversion needs manual review, by a member of the verification team who can reveal the code solely to confirm that balance. A support reply will never quote your card code back to you.

No passwords

There's no password to phish or leak. You sign in with a one-time link we email you, or with a passkey on your device. Either way, only someone with access to your inbox or your device can open your account.

The anti-phishing pledge

We only ever ask for a card code on the convert page itself — never by email, DM, or phone. If a message asks otherwise, it's not from us.

Report a concern

Seen something that looks like us but smells wrong, or found a weakness you think we should know about? Write to support@gc4.ai. A person reads every message. This page describes our current posture; we'll update it here whenever it changes.