Security built into every transaction.

Security built into every transaction.

Security built into every transaction.

Guardian is the composable token vault that takes your systems out of PCI scope. Vault, tokenize, and verify every payment on dedicated infrastructure you control.

Guardian is the composable token vault that takes your systems out of PCI scope. Vault, tokenize, and verify every payment on dedicated infrastructure you control.

Guardian is the composable token vault that takes your systems out of PCI scope. Vault, tokenize, and verify every payment on dedicated infrastructure you control.

SAQ A descoping

Network token lifecycle

API-first proxy

Dedicated infrastructure

https://hellgate.io/guardian

Hellgate Guardian token dashboard

Built on the Hellgate Cloud Platform. Works with the card networks and PSPs you already use.

Visa Token Service

Mastercard MDES

Any PSP or acquirer

The problem

Storing card data is risky and costly.

PCI compliance shouldn’t hold back innovation, but most teams still juggle vaulting, audits, and token management on their own.

PCI compliance overhead

SAQ D means hundreds of controls, file-integrity monitoring, and annual on-site audits, consuming engineering time you would rather spend on product.

Data fragmentation and exposure

Sensitive card data spread across multiple systems widens your attack surface, and your compliance scope, with every new integration.

Vendor lock-in

Proprietary tokens chain your volume to one processor. You can’t route, A/B test acquirers, or migrate without forcing customers to re-enter cards.

Why Guardian

One secure layer between you and every card credential.

A universal vault and tokenization system, built for the complex part of the payments world.

Merchant

Guardian

Vault and tokenization

PSPs and acquirers

Out of PCI scope by design

A proxy architecture keeps raw card data off your servers, dropping you from SAQ D to SAQ A on dedicated infrastructure provisioned for you.

Tokens you own

Universal tokens work with any PSP or acquirer, so you can route, fail over, and migrate volume without ever touching a credential.

One simple integration

A single API-first integration covers vaulting, network tokens, account updater, and identity verification.

Integration

Two ways to plug in. Both invisible to your customers.

Call Guardian directly, or slot its proxy transparently between your checkout and your PSP.

API mode

A direct call to Guardian’s API to vault, tokenize, or resolve a credential.

Vault a card and receive a universal Hellgate token

Network tokens provisioned and refreshed automatically

Identity and verification run inline or asynchronously

Proxy mode

Guardian’s proxy sits transparently between your checkout and your PSP.

No change to your customer-facing flow

Inbound proxy captures the raw PAN before it reaches your servers

Outbound proxy resolves the token and injects the PAN to the PSP

PATTERN 01

Vault and tokenize

Capture the card, store it in the PCI vault, and return a token your systems can safely reuse.

PATTERN 02

Network tokenization

Provision Visa and Mastercard network tokens, with dynamic cryptograms that lift authorization rates.

PATTERN 03

Inbound proxy

Intercept the raw PAN in the consumer request and tokenize it before it ever touches your backend.

PATTERN 04

Outbound proxy

Resolve a token and inject the PAN directly to the acquirer of your choice at authorization time.

Token services

Every credential service,
in one vault.

Run them standalone or compose them, all from a single PCI-aligned vault.

PCI-compliant vaulting

Store cardholder data inside a PCI-certified vault. Raw PANs never touch your systems, removing PCI scope from your environment.

vault

tokenize

proxy

SAQ A

Network tokens & updater

Provision and refresh Visa and Mastercard network tokens, and keep cards on file current with Account Updater to stop silent churn.

VTS

MDES

updater

cryptograms

Identity & verification

Validate cards, identities, and devices in real time with 3DS 2.x and risk-based checks, fully aligned with PSD2 and SCA.

SAQ A

Descoped from SAQ D via the proxy

+2-4%

Auth uplift from network tokens

~0%

Involuntary churn with Account Updater

Token lifecycle

From first card to renewal, in one system.

Every credential is vaulted once, then tokenized, verified, and kept current automatically, so payments keep flowing without re-entry.

Vault

Tokenize

Verify

Authorization

Capture

Network token

Account updater

Re-auth

Renewal

Inside Guardian

See every token. Manage every credential.

A console built for payment teams, from live tokens down to the card behind each one.

A live view of every token

Track every Hellgate token across schemes and accounts, with network-token status, ID&V state, and creation date at a glance.

  • Filter by scheme, network token, or date
  • Search by last 4 digits or token ID
  • Export a full report in one click
Hellgate token dashboard

Composable

One product in the Hellgate Cloud Platform.

Run Guardian on its own, or compose it freely with other Hellgate products as your needs grow.

You are here

Guardian

Token vault with network tokenization.

Specter

Real-time risk and fraud decisions.

Link

Rapid protocol and backend integration.

Pricing

Scale on your terms.

Pick an infrastructure tier with unlimited token storage, no overage penalties, and universal token portability. A single per-token issuance fee applies.

S

Small

€1,000

/ month

Production tier

up to 2,5M credentials on file

Additional Network Token issuance fee applies = one time per token, usage is free

Dedicated, single-tenant vault

Tokenization SDK

Processor-agnostic vault + secure forwarding

Network tokenization & enrichment

Token import & export - no lock-in

SAQ-A scope reduction - PCI DSS by design

Account Updater Fee €0.23

Meta Data Fee per request €0.06

Composable with the full Hellgate stack

M

Medium

€5,800

/ month

Production tier

up to 15M credentials on file

Additional Network Token issuance fee applies = one time per token, usage is free

Dedicated, single-tenant vault

Tokenization SDK

Processor-agnostic vault + secure forwarding

Network tokenization & enrichment

Token import & export - no lock-in

SAQ-A scope reduction - PCI DSS by design

Account Updater Fee €0.20

Meta Data Fee per request €0.05

Composable with the full Hellgate stack

Most popular

L

Large

€12,500

/ month

Production tier

up to 25M credentials on file

Additional Network Token issuance fee applies = one time per token, usage is free

Dedicated, single-tenant vault

Tokenization SDK

Processor-agnostic vault + secure forwarding

Network tokenization & enrichment

Token import & export - no lock-in

SAQ-A scope reduction - PCI DSS by design

Account Updater Fee €0.18

Meta Data Fee per request €0.04

Composable with the full Hellgate stack

Add-on Services

Enabling efficient orchestration, expanding merchant access, and powering embedded finance models.

Network Tokens

Manages lifecycle of network tokens (Visa, Mastercard, etc.)

Enables secure token provisioning and refreshing

Enables processing over different PSPs and Acquirers

Optional fallback for PAN vaulting

Build modern, user-friendly authentication flows aligned with PSD2 and beyond with delegated authentication

Account Updater

Keeps stored CHD actual and refreshes if needed

Reduces transaction failures through expired, replaced, reissued CHD

Is integrated with VISA (Account Updater) and Mastercard (Automatic Billing Updater)

Improves authorization rates

Improves customer retention, esp. for loyalty programs and recurring billings

Identification and Verification for Tokens

Fully compliant with EMV 3DS 2.x protocol

Supports both frictionless and challenge flows

Designed for seamless use across multiple PSPs and Acquirers

Compatible with PSD2/SCA and global authentication mandates

Card Metadata Service

Provides Card Metadata, like Issuer, BIN, and country

Delivers card types, scheme affiliation and feature flags

Provides the fuel to improve routing scenarios and customer analytics

BOOK A DEMO

See Guardian in action

See Guardian in action

See Guardian in action

Walk through a live Guardian setup with our team. We'll map your tokenization architecture, show you how card data stays out of your systems, and cover the integration paths that fit your stack

Review of your current tokenization and PCI compliance setup

Live walkthrough of PCI tokens, network tokens, and forwarding

Token import: Migrate your existing vault without re-tokenizing

Live Q&A with a payments engineer

Book your demo with our payments engineers

Trusted by enterprise clients

FAQ

FAQ

FAQ

What is Hellgate Guardian?

Guardian is Hellgate's fully PCI-compliant tokenization service, delivered as managed, dedicated infrastructure. It sits as a protective yet actionable layer between your services and the sensitive data it stores – primarily card credentials – replacing raw data with tokens your systems can safely handle.

By taking sensitive data out of scope, Guardian unlocks composability: you can combine payment services freely without each one dragging PCI scope, compliance, and data-protection obligations along with it.

→ Explore Guardian

Label

Can Guardian be used standalone?

Yes. Guardian is a standalone CPA component, fully independent of Hub or Commerce. Many organisations adopt Guardian on its own purely to cut PCI scope – vaulting card data with Hellgate while keeping their existing payment stack – and compose other services later if they choose.

It also works naturally alongside other Hellgate services: Specter, for example, can read token-level signals from Guardian to sharpen fraud scoring.

→ Use Guardian standalone

Label

How does Guardian reduce PCI DSS scope?

When you route card data through Guardian, the data lives entirely inside a PCI DSS Level 1 certified cardholder data environment operated by Hellgate – not in your own infrastructure. Your systems only ever handle non-sensitive tokens.

Because your environment never touches the PAN, it falls outside the most demanding PCI requirements. In practice this often moves a merchant from SAQ D (hundreds of controls) to a far lighter SAQ A or SAQ A-EP self-assessment.

→ See Hellgate's Trustcenter

Label

What is a credit card vault and how does it work?

A credit card vault is a PCI DSS-certified environment that stores cardholder data – primarily Primary Account Numbers (PANs) – on behalf of a merchant. Instead of storing raw card data yourself, you store a token: a non-sensitive reference that maps back to the original credential inside the vault.

Because your infrastructure never holds the PAN, it falls outside the most demanding PCI controls, dramatically reducing your compliance burden while you still transact normally using the token.

→ Guardian handles PCI vaulting for enterprise merchants

Label

Does Guardian only handle card data?

Cards are the primary use case, but Guardian is not limited to them. Alongside PCI tokens for payment credentials, it offers generic tokens that store arbitrary sensitive payloads – for example SEPA bank details, API keys, or personally identifiable information (PII).

That makes Guardian useful for GDPR-driven data-protection needs as well as PCI: any sensitive value your systems shouldn't hold in the clear can be vaulted and referenced by token.

→ See generic tokens

Label

What token types does Guardian support?

Guardian supports four token types. PCI tokens (standard) protect card credentials and keep raw PANs out of your systems. Generic tokens (standard) store arbitrary sensitive payloads such as SEPA credentials or PII. Network tokens (add-on) are scheme-issued tokens for higher authorization and lower fraud. Metadata inquiries (add-on) return card and issuing-bank data for display, validation, routing, and analytics.

Add-on features are enabled per account through your Hellgate representative.

→ Compare Guardian token types

Label

How do network tokens improve authorization rates?

Network tokens replace the card PAN with a scheme-issued token that the card networks keep continuously updated. When a customer's card is reissued or its expiry changes, the token still works – so recurring and subscription payments don't fail at renewal.

Because they carry richer, verified data and reduce reliance on static PANs, network tokens typically lift authorization rates, reduce declines, and mitigate fraud. Guardian can provision them from a session, PAN, or existing PCI token.

→ Learn about network tokens

Label

Can I migrate existing tokens into Guardian?

Yes. Guardian supports both PCI token import and export, so you can migrate stored credentials from another vault into Guardian – and move them out again if you ever need to. Migration flows are documented and designed to run without disrupting live transactions.

Portable tokens are a deliberate anti-lock-in feature: your data stays yours, which is central to the CPA philosophy.

→ See token migration

Label

Is Guardian delivered on dedicated infrastructure?

Yes. Guardian is delivered as managed, dedicated single-tenant infrastructure: your instance is provisioned exclusively for your organisation, with compute, storage, and network never shared with other clients. Your payment data is physically isolated, with no possibility of cross-tenant access.

Hellgate operates and manages the infrastructure on your behalf, but full data ownership stays with you – and you can choose an Azure region close to your workloads for latency and data-residency reasons.

→ Getting access to Guardian

Label

How does Guardian support PCI DSS v4.0 compliance?

Guardian is operated as a PCI DSS Level 1 certified service. When you route card data through it, that data lives entirely within Hellgate's certified cardholder data environment rather than your own infrastructure, so you can significantly reduce your PCI scope and often qualify for lighter self-assessment questionnaires (SAQ A or SAQ A-EP).

Guardian also supports v4.0 requirements such as customised implementation of multi-factor authentication and encrypted data transmission.

→ Hellgate Trustcenter

Label

What are metadata inquiries and why do they matter?

Metadata inquiries let you retrieve comprehensive card and issuing-bank information from a PAN, a PCI token, or a network token – without exposing the underlying sensitive data. Typical uses include displaying card brand and last four digits, validating a card, making routing decisions (for example, sending a transaction to the acquirer with the best rate for that issuer), and enriching analytics.

It's an add-on feature that turns vaulted data into actionable signal while keeping it protected.

→ See metadata inquiries

Label

Does Guardian help with GDPR and PII data protection?

Yes. Beyond cards, Guardian's generic tokens can vault other categories of sensitive and personally identifiable information, so PII never sits in the clear in your own systems. Combined with dedicated, single-tenant infrastructure and your choice of Azure region for data residency, this supports GDPR obligations around data minimisation, protection, and locality.

You keep full ownership of the data, while Guardian provides the certified environment that holds it.

→ How Guardian protects sensitive data

Label

How does forwarding sensitive data work without touching my systems?

Guardian's forwarding lets you send card data to a certified third-party provider without that data ever passing through your infrastructure. You reference a token; Guardian injects the sensitive value (card data, or a network-token cryptogram) into the outbound request server-side, then forwards it.

This is how SAQ-A merchants can, for example, use network tokens or connect to a new processor without ever handling a raw PAN or cryptogram themselves.

→ See secure forwarding

Label

What is a credit card vault and how does it reduce PCI scope?

A credit card vault is a PCI DSS-certified environment that stores cardholder data – primarily Primary Account Numbers (PANs) – on behalf of a merchant. Instead of storing raw card data in your own systems, you store a token: a non-sensitive reference that maps back to the original credential inside the vault.

Because your own infrastructure never touches the PAN, it falls outside the most demanding PCI DSS requirements. The result is a dramatically reduced compliance scope – typically from SAQ D (hundreds of controls) to SAQ A (a short self-assessment).

→ Hellgate Guardian handles PCI vaulting for enterprise merchants · Full guide: Credit Card Vault

Label