SAQ A descoping
Network token lifecycle
API-first proxy
Dedicated infrastructure
https://hellgate.io/guardian

Built on the Hellgate Cloud Platform. Works with the card networks and PSPs you already use.

Visa Token Service

Mastercard MDES
Any PSP or acquirer
The problem
Storing card data is risky and costly.
PCI compliance shouldn’t hold back innovation, but most teams still juggle vaulting, audits, and token management on their own.
PCI compliance overhead
SAQ D means hundreds of controls, file-integrity monitoring, and annual on-site audits, consuming engineering time you would rather spend on product.
Data fragmentation and exposure
Sensitive card data spread across multiple systems widens your attack surface, and your compliance scope, with every new integration.
Vendor lock-in
Proprietary tokens chain your volume to one processor. You can’t route, A/B test acquirers, or migrate without forcing customers to re-enter cards.
Why Guardian
One secure layer between you and every card credential.
A universal vault and tokenization system, built for the complex part of the payments world.
Merchant
Guardian
Vault and tokenization
PSPs and acquirers



Out of PCI scope by design
A proxy architecture keeps raw card data off your servers, dropping you from SAQ D to SAQ A on dedicated infrastructure provisioned for you.
Tokens you own
Universal tokens work with any PSP or acquirer, so you can route, fail over, and migrate volume without ever touching a credential.
One simple integration
A single API-first integration covers vaulting, network tokens, account updater, and identity verification.
Integration
Two ways to plug in. Both invisible to your customers.
Call Guardian directly, or slot its proxy transparently between your checkout and your PSP.
API mode
A direct call to Guardian’s API to vault, tokenize, or resolve a credential.
Vault a card and receive a universal Hellgate token
Network tokens provisioned and refreshed automatically
Identity and verification run inline or asynchronously
Proxy mode
Guardian’s proxy sits transparently between your checkout and your PSP.
No change to your customer-facing flow
Inbound proxy captures the raw PAN before it reaches your servers
Outbound proxy resolves the token and injects the PAN to the PSP
PATTERN 01
Vault and tokenize
Capture the card, store it in the PCI vault, and return a token your systems can safely reuse.
PATTERN 02
Network tokenization
Provision Visa and Mastercard network tokens, with dynamic cryptograms that lift authorization rates.
PATTERN 03
Inbound proxy
Intercept the raw PAN in the consumer request and tokenize it before it ever touches your backend.
PATTERN 04
Outbound proxy
Resolve a token and inject the PAN directly to the acquirer of your choice at authorization time.
Token services
Every credential service,
in one vault.
Run them standalone or compose them, all from a single PCI-aligned vault.
PCI-compliant vaulting
Store cardholder data inside a PCI-certified vault. Raw PANs never touch your systems, removing PCI scope from your environment.
vault
tokenize
proxy
SAQ A
Network tokens & updater
Provision and refresh Visa and Mastercard network tokens, and keep cards on file current with Account Updater to stop silent churn.
VTS
MDES
updater
cryptograms
Identity & verification
Validate cards, identities, and devices in real time with 3DS 2.x and risk-based checks, fully aligned with PSD2 and SCA.
SAQ A
Descoped from SAQ D via the proxy
+2-4%
Auth uplift from network tokens
~0%
Involuntary churn with Account Updater
Token lifecycle
From first card to renewal, in one system.
Every credential is vaulted once, then tokenized, verified, and kept current automatically, so payments keep flowing without re-entry.
Vault
Tokenize
Verify
Authorization
Capture
Network token
Account updater
Re-auth
Renewal
Inside Guardian
See every token. Manage every credential.
A console built for payment teams, from live tokens down to the card behind each one.
A live view of every token
Track every Hellgate token across schemes and accounts, with network-token status, ID&V state, and creation date at a glance.
- Filter by scheme, network token, or date
- Search by last 4 digits or token ID
- Export a full report in one click
Composable
One product in the Hellgate Cloud Platform.
Run Guardian on its own, or compose it freely with other Hellgate products as your needs grow.
You are here
Guardian
Token vault with network tokenization.
Specter
Real-time risk and fraud decisions.
Link
Rapid protocol and backend integration.
Pricing
Scale on your terms.
Pick an infrastructure tier with unlimited token storage, no overage penalties, and universal token portability. A single per-token issuance fee applies.
S
Small
€1,000
/ month
Production tier
up to 2,5M credentials on file
Additional Network Token issuance fee applies = one time per token, usage is free
Dedicated, single-tenant vault
Tokenization SDK
Processor-agnostic vault + secure forwarding
Network tokenization & enrichment
Token import & export - no lock-in
SAQ-A scope reduction - PCI DSS by design
Account Updater Fee €0.23
Meta Data Fee per request €0.06
Composable with the full Hellgate stack
M
Medium
€5,800
/ month
Production tier
up to 15M credentials on file
Additional Network Token issuance fee applies = one time per token, usage is free
Dedicated, single-tenant vault
Tokenization SDK
Processor-agnostic vault + secure forwarding
Network tokenization & enrichment
Token import & export - no lock-in
SAQ-A scope reduction - PCI DSS by design
Account Updater Fee €0.20
Meta Data Fee per request €0.05
Composable with the full Hellgate stack
Most popular
L
Large
€12,500
/ month
Production tier
up to 25M credentials on file
Additional Network Token issuance fee applies = one time per token, usage is free
Dedicated, single-tenant vault
Tokenization SDK
Processor-agnostic vault + secure forwarding
Network tokenization & enrichment
Token import & export - no lock-in
SAQ-A scope reduction - PCI DSS by design
Account Updater Fee €0.18
Meta Data Fee per request €0.04
Composable with the full Hellgate stack
Add-on Services
Enabling efficient orchestration, expanding merchant access, and powering embedded finance models.
Network Tokens
Manages lifecycle of network tokens (Visa, Mastercard, etc.)
Enables secure token provisioning and refreshing
Enables processing over different PSPs and Acquirers
Optional fallback for PAN vaulting
Build modern, user-friendly authentication flows aligned with PSD2 and beyond with delegated authentication
Account Updater
Keeps stored CHD actual and refreshes if needed
Reduces transaction failures through expired, replaced, reissued CHD
Is integrated with VISA (Account Updater) and Mastercard (Automatic Billing Updater)
Improves authorization rates
Improves customer retention, esp. for loyalty programs and recurring billings
Fully compliant with EMV 3DS 2.x protocol
Supports both frictionless and challenge flows
Designed for seamless use across multiple PSPs and Acquirers
Compatible with PSD2/SCA and global authentication mandates
Card Metadata Service
Provides Card Metadata, like Issuer, BIN, and country
Delivers card types, scheme affiliation and feature flags
Provides the fuel to improve routing scenarios and customer analytics
BOOK A DEMO
Walk through a live Guardian setup with our team. We'll map your tokenization architecture, show you how card data stays out of your systems, and cover the integration paths that fit your stack
Review of your current tokenization and PCI compliance setup
Live walkthrough of PCI tokens, network tokens, and forwarding
Token import: Migrate your existing vault without re-tokenizing
Live Q&A with a payments engineer
Trusted by enterprise clients
What is Hellgate Guardian?
Guardian is Hellgate's fully PCI-compliant tokenization service, delivered as managed, dedicated infrastructure. It sits as a protective yet actionable layer between your services and the sensitive data it stores – primarily card credentials – replacing raw data with tokens your systems can safely handle.
By taking sensitive data out of scope, Guardian unlocks composability: you can combine payment services freely without each one dragging PCI scope, compliance, and data-protection obligations along with it.
Label
Can Guardian be used standalone?
Yes. Guardian is a standalone CPA component, fully independent of Hub or Commerce. Many organisations adopt Guardian on its own purely to cut PCI scope – vaulting card data with Hellgate while keeping their existing payment stack – and compose other services later if they choose.
It also works naturally alongside other Hellgate services: Specter, for example, can read token-level signals from Guardian to sharpen fraud scoring.
Label
How does Guardian reduce PCI DSS scope?
When you route card data through Guardian, the data lives entirely inside a PCI DSS Level 1 certified cardholder data environment operated by Hellgate – not in your own infrastructure. Your systems only ever handle non-sensitive tokens.
Because your environment never touches the PAN, it falls outside the most demanding PCI requirements. In practice this often moves a merchant from SAQ D (hundreds of controls) to a far lighter SAQ A or SAQ A-EP self-assessment.
Label
What is a credit card vault and how does it work?
A credit card vault is a PCI DSS-certified environment that stores cardholder data – primarily Primary Account Numbers (PANs) – on behalf of a merchant. Instead of storing raw card data yourself, you store a token: a non-sensitive reference that maps back to the original credential inside the vault.
Because your infrastructure never holds the PAN, it falls outside the most demanding PCI controls, dramatically reducing your compliance burden while you still transact normally using the token.
Label
Does Guardian only handle card data?
Cards are the primary use case, but Guardian is not limited to them. Alongside PCI tokens for payment credentials, it offers generic tokens that store arbitrary sensitive payloads – for example SEPA bank details, API keys, or personally identifiable information (PII).
That makes Guardian useful for GDPR-driven data-protection needs as well as PCI: any sensitive value your systems shouldn't hold in the clear can be vaulted and referenced by token.
Label
What token types does Guardian support?
Guardian supports four token types. PCI tokens (standard) protect card credentials and keep raw PANs out of your systems. Generic tokens (standard) store arbitrary sensitive payloads such as SEPA credentials or PII. Network tokens (add-on) are scheme-issued tokens for higher authorization and lower fraud. Metadata inquiries (add-on) return card and issuing-bank data for display, validation, routing, and analytics.
Add-on features are enabled per account through your Hellgate representative.
Label
How do network tokens improve authorization rates?
Network tokens replace the card PAN with a scheme-issued token that the card networks keep continuously updated. When a customer's card is reissued or its expiry changes, the token still works – so recurring and subscription payments don't fail at renewal.
Because they carry richer, verified data and reduce reliance on static PANs, network tokens typically lift authorization rates, reduce declines, and mitigate fraud. Guardian can provision them from a session, PAN, or existing PCI token.
Label
Can I migrate existing tokens into Guardian?
Yes. Guardian supports both PCI token import and export, so you can migrate stored credentials from another vault into Guardian – and move them out again if you ever need to. Migration flows are documented and designed to run without disrupting live transactions.
Portable tokens are a deliberate anti-lock-in feature: your data stays yours, which is central to the CPA philosophy.
Label
Is Guardian delivered on dedicated infrastructure?
Yes. Guardian is delivered as managed, dedicated single-tenant infrastructure: your instance is provisioned exclusively for your organisation, with compute, storage, and network never shared with other clients. Your payment data is physically isolated, with no possibility of cross-tenant access.
Hellgate operates and manages the infrastructure on your behalf, but full data ownership stays with you – and you can choose an Azure region close to your workloads for latency and data-residency reasons.
Label
How does Guardian support PCI DSS v4.0 compliance?
Guardian is operated as a PCI DSS Level 1 certified service. When you route card data through it, that data lives entirely within Hellgate's certified cardholder data environment rather than your own infrastructure, so you can significantly reduce your PCI scope and often qualify for lighter self-assessment questionnaires (SAQ A or SAQ A-EP).
Guardian also supports v4.0 requirements such as customised implementation of multi-factor authentication and encrypted data transmission.
Label
What are metadata inquiries and why do they matter?
Metadata inquiries let you retrieve comprehensive card and issuing-bank information from a PAN, a PCI token, or a network token – without exposing the underlying sensitive data. Typical uses include displaying card brand and last four digits, validating a card, making routing decisions (for example, sending a transaction to the acquirer with the best rate for that issuer), and enriching analytics.
It's an add-on feature that turns vaulted data into actionable signal while keeping it protected.
Label
Does Guardian help with GDPR and PII data protection?
Yes. Beyond cards, Guardian's generic tokens can vault other categories of sensitive and personally identifiable information, so PII never sits in the clear in your own systems. Combined with dedicated, single-tenant infrastructure and your choice of Azure region for data residency, this supports GDPR obligations around data minimisation, protection, and locality.
You keep full ownership of the data, while Guardian provides the certified environment that holds it.
Label
How does forwarding sensitive data work without touching my systems?
Guardian's forwarding lets you send card data to a certified third-party provider without that data ever passing through your infrastructure. You reference a token; Guardian injects the sensitive value (card data, or a network-token cryptogram) into the outbound request server-side, then forwards it.
This is how SAQ-A merchants can, for example, use network tokens or connect to a new processor without ever handling a raw PAN or cryptogram themselves.
Label
What is a credit card vault and how does it reduce PCI scope?
A credit card vault is a PCI DSS-certified environment that stores cardholder data – primarily Primary Account Numbers (PANs) – on behalf of a merchant. Instead of storing raw card data in your own systems, you store a token: a non-sensitive reference that maps back to the original credential inside the vault.
Because your own infrastructure never touches the PAN, it falls outside the most demanding PCI DSS requirements. The result is a dramatically reduced compliance scope – typically from SAQ D (hundreds of controls) to SAQ A (a short self-assessment).
→ Hellgate Guardian handles PCI vaulting for enterprise merchants · Full guide: Credit Card Vault
Label






