GUARDIAN
Take control of your authorization rates
Guardian gives you the tokenized foundation to route intelligently, detect fraud natively, and monitor every transaction in real time.
THE PROBLEM
Your single-PSP setup has a ceiling.
When one provider handles everything, you lose the granular control that separates good payment operations from great ones.
No acquirer competition
Blind optimization
Fragmented fraud stack
Composable Payment Architecture
Four modules. Total control.
Guardian is the tokenized foundation.
Compose it with Hub, Specter, and Pulse to build a payment stack optimized for your KPIs.
Guardian
Vault & Tokenization
Hub
Smart Routing
Specter
Fraud Intelligence
Pulse
Observability
Each module works independently or together. Start with Guardian for
tokenization, then compose Hub, Specter, and Pulse as your needs grow.
See how Guardian can transform your payment operations.
Capabilities
Every lever. One platform.
Guardian combined with the CPA gives you the tools to optimize authorization rates, reduce fraud, and monitor everything.
Multi-acquirer routing
Routing decision tree illustration
Native fraud scoring
Routing decision tree illustration
Real-time payment observability
97.3%
Auth rate
0.12%
Chargeback Rate
23ms
Median latency
Network Token lifecycle
Dynamic cryptograms from Visa and Mastercard boost issuer trust. Account Updater automatically refreshes expiring credentials, protecting subscription revenue from silent churn.
True data sovereignty
Use Cases
Built for your payment challenges.
Guardian serves as the secure foundation for the payment operations that matter most to your business.
Multi-acquirer routing
Optimize globally by routing to the best acquirer per market.
Route by region, BIN, card type
Failover between processors
A/B test acquirer performance
Subscription protection
Eliminate involuntary churn from expiring card credentials.
Auto-refresh via Account Updater
Network Token lifecycle
Zero customer intervention
Marketplace payments
Secure multi-party payment flows for complex marketplace models.
Tokenize across sellers
PCI descoping for platform
Route per-seller to optimal PSP
Trusted by enterprise payment teams
"By moving to Guardian's token vault,
we finally took back control of our customers' payment credentials.
We're now able to keep cards on file automatically updated behind the scenes,
and we have the total freedom to steer our
payment flows directly to our preferred gateways."
Head of Payments
at a high-volume European merchant
OPERATIONAL COMPARISON
More control. Better outcomes.
How Guardian and Hellgate Cloud Platform compares to monolithic PSPs on the KPIs that drive your payment strategy.
Operational Factor
Monolithic PSP
Hellgate Guardian
Acquirer routing
Single processor. No ability to A/B test or failover between acquirers.
Route by region, BIN, card type, or cost. Automatic failover via Hub orchestration.
Auth rate optimization
Dependent on PSP's internal optimization. No independent benchmarking.
Network Tokens with dynamic cryptograms increase issuer trust. Account Updater prevents silent declines.
Fraud intelligence
Bundled fraud tools. Limited to what the PSP offers. Adding external engines expands PCI scope.
Native Specter integration with Visa Decision Manager. Real-time scoring without exposing raw data.
Payment observability
PSP-reported dashboards. No independent event streaming or anomaly detection.
Pulse streams real-time events across the full flow. Independent anomaly detection and performance tracking.
Vendor independence
Proprietary tokens. Migration requires customer re-entry of card details.
Universal tokens belong to you. Move volume to any acquirer without customer intervention.
Credential lifecycle
Basic updater services. Inconsistent coverage across card networks.
Visa + Mastercard Account Updater with automatic fallback from Network Tokens to vault tokens.
"Monolithic PSP" reflects common limitations of bundled payment platforms. Hellgate CPA capabilities per developer.hellgate.io
AGENTIC COMMERCE READY
When agents start transacting, your controls still apply.
AI-initiated payments flow through the same Guardian vault, Hub routing, Specter fraud scoring, and Pulse observability as human-initiated transactions. No control gaps.
Side-by-side flow comparison: human checkout and AI
agent both converging into the same CPA pipeline
(Guardian > Hub > Specter > Pulse). Identical controls,
different initiation point.
Today
Human commerce
Emerging
Hybrid flows
Next
Autonomous agents
Routing rules persist
Agent transactions follow the same Hub routing logic. Cost-based, region-based, and performance-based rules apply automatically.
Fraud controls hold
Specter scores every transaction identically, regardless of whether a human or agent initiated it. No gaps in fraud coverage.
Full observability
Pulse streams agent-initiated events into the same dashboards. Track auth rates, anomalies, and performance across all transaction types.
PRICING
Scale on your terms
Our usage-based pricing is built for growth
- with no hidden fees, no surprises, and no friction.
Playground
0.28 EUR
per hour
5000 tokens
Development Tier
SAQ/A, A-EP, D
Single node
EU region only
Network Token support
DAuth Support
DEV
Hello World
0.56 EUR
per hour
Unlimited Tokens
Production Tier
SAQ/A
Single node
EU region only
S
Go Live
1,000 EUR
per month
Everything in "Hello World" Plan
Cluster M
EU and US region
Network Token support ¹
M
Think Global
5,800 EUR
per month
Everything in "Go Live" Plan
SAQ/A, D
Cluster L
All regions
Network Token support ²
L
Think Big
12,500 EUR
per month
Everything in "Think Global" plan
SAQ/A, D, RoC
Cluster XL
High Availability
Network Token support 3
XL
God Mode
Contact us
Everything in "Think Big" Plan
Cluster XXL
DAuth Support
Extension Support
Network Token support 4
XXL
ADD-ONS
Add-on Services
Enabling efficient orchestration, expanding merchant access, and powering embedded finance models.
Network Tokens
Manages lifecycle of network tokens (Visa, Mastercard, etc.)
Enables secure token provisioning and refreshing
Enables processing over different PSPs and Acquirers
Optional fallback for PAN vaulting
Build modern, user-friendly authentication flows aligned with PSD2 and beyond with delegated authentication
Account Updater
Keeps stored CHD actual and refreshes if needed
Reduces transaction failures through expired, replaced, reissued CHD
Is integrated with VISA (Account Updater) and Mastercard (Automatic Billing Updater)
Improves authorization rates
Improves customer retention, esp. for loyalty programs and recurring billings
Identification and Verification for Tokens
Fully compliant with EMV 3DS 2.x protocol
Supports both frictionless and challenge flows
Designed for seamless use across multiple PSPs and Acquirers
Compatible with PSD2/SCA and global authentication mandates
Card Metadata Service
Provides Card Metadata, like Issuer, BIN, and country
Delivers card types, scheme affiliation and feature flags
Provides the fuel to improve routing scenarios and customer analytics
What is Hellgate Guardian?
Guardian is Hellgate's fully PCI-compliant tokenization service, delivered as managed, dedicated infrastructure. It sits as a protective yet actionable layer between your services and the sensitive data it stores – primarily card credentials – replacing raw data with tokens your systems can safely handle.
By taking sensitive data out of scope, Guardian unlocks composability: you can combine payment services freely without each one dragging PCI scope, compliance, and data-protection obligations along with it.
Label
Can Guardian be used standalone?
Yes. Guardian is a standalone CPA component, fully independent of Hub or Commerce. Many organisations adopt Guardian on its own purely to cut PCI scope – vaulting card data with Hellgate while keeping their existing payment stack – and compose other services later if they choose.
It also works naturally alongside other Hellgate services: Specter, for example, can read token-level signals from Guardian to sharpen fraud scoring.
Label
How does Guardian reduce PCI DSS scope?
When you route card data through Guardian, the data lives entirely inside a PCI DSS Level 1 certified cardholder data environment operated by Hellgate – not in your own infrastructure. Your systems only ever handle non-sensitive tokens.
Because your environment never touches the PAN, it falls outside the most demanding PCI requirements. In practice this often moves a merchant from SAQ D (hundreds of controls) to a far lighter SAQ A or SAQ A-EP self-assessment.
Label
What is a credit card vault and how does it work?
A credit card vault is a PCI DSS-certified environment that stores cardholder data – primarily Primary Account Numbers (PANs) – on behalf of a merchant. Instead of storing raw card data yourself, you store a token: a non-sensitive reference that maps back to the original credential inside the vault.
Because your infrastructure never holds the PAN, it falls outside the most demanding PCI controls, dramatically reducing your compliance burden while you still transact normally using the token.
Label
Does Guardian only handle card data?
Cards are the primary use case, but Guardian is not limited to them. Alongside PCI tokens for payment credentials, it offers generic tokens that store arbitrary sensitive payloads – for example SEPA bank details, API keys, or personally identifiable information (PII).
That makes Guardian useful for GDPR-driven data-protection needs as well as PCI: any sensitive value your systems shouldn't hold in the clear can be vaulted and referenced by token.
Label
What token types does Guardian support?
Guardian supports four token types. PCI tokens (standard) protect card credentials and keep raw PANs out of your systems. Generic tokens (standard) store arbitrary sensitive payloads such as SEPA credentials or PII. Network tokens (add-on) are scheme-issued tokens for higher authorization and lower fraud. Metadata inquiries (add-on) return card and issuing-bank data for display, validation, routing, and analytics.
Add-on features are enabled per account through your Hellgate representative.
Label
How do network tokens improve authorization rates?
Network tokens replace the card PAN with a scheme-issued token that the card networks keep continuously updated. When a customer's card is reissued or its expiry changes, the token still works – so recurring and subscription payments don't fail at renewal.
Because they carry richer, verified data and reduce reliance on static PANs, network tokens typically lift authorization rates, reduce declines, and mitigate fraud. Guardian can provision them from a session, PAN, or existing PCI token.
Label
Can I migrate existing tokens into Guardian?
Yes. Guardian supports both PCI token import and export, so you can migrate stored credentials from another vault into Guardian – and move them out again if you ever need to. Migration flows are documented and designed to run without disrupting live transactions.
Portable tokens are a deliberate anti-lock-in feature: your data stays yours, which is central to the CPA philosophy.
Label
Is Guardian delivered on dedicated infrastructure?
Yes. Guardian is delivered as managed, dedicated single-tenant infrastructure: your instance is provisioned exclusively for your organisation, with compute, storage, and network never shared with other clients. Your payment data is physically isolated, with no possibility of cross-tenant access.
Hellgate operates and manages the infrastructure on your behalf, but full data ownership stays with you – and you can choose an Azure region close to your workloads for latency and data-residency reasons.
Label
How does Guardian support PCI DSS v4.0 compliance?
Guardian is operated as a PCI DSS Level 1 certified service. When you route card data through it, that data lives entirely within Hellgate's certified cardholder data environment rather than your own infrastructure, so you can significantly reduce your PCI scope and often qualify for lighter self-assessment questionnaires (SAQ A or SAQ A-EP).
Guardian also supports v4.0 requirements such as customised implementation of multi-factor authentication and encrypted data transmission.
Label
What are metadata inquiries and why do they matter?
Metadata inquiries let you retrieve comprehensive card and issuing-bank information from a PAN, a PCI token, or a network token – without exposing the underlying sensitive data. Typical uses include displaying card brand and last four digits, validating a card, making routing decisions (for example, sending a transaction to the acquirer with the best rate for that issuer), and enriching analytics.
It's an add-on feature that turns vaulted data into actionable signal while keeping it protected.
Label
Does Guardian help with GDPR and PII data protection?
Yes. Beyond cards, Guardian's generic tokens can vault other categories of sensitive and personally identifiable information, so PII never sits in the clear in your own systems. Combined with dedicated, single-tenant infrastructure and your choice of Azure region for data residency, this supports GDPR obligations around data minimisation, protection, and locality.
You keep full ownership of the data, while Guardian provides the certified environment that holds it.
Label
How does forwarding sensitive data work without touching my systems?
Guardian's forwarding lets you send card data to a certified third-party provider without that data ever passing through your infrastructure. You reference a token; Guardian injects the sensitive value (card data, or a network-token cryptogram) into the outbound request server-side, then forwards it.
This is how SAQ-A merchants can, for example, use network tokens or connect to a new processor without ever handling a raw PAN or cryptogram themselves.
Label
What is a credit card vault and how does it reduce PCI scope?
A credit card vault is a PCI DSS-certified environment that stores cardholder data – primarily Primary Account Numbers (PANs) – on behalf of a merchant. Instead of storing raw card data in your own systems, you store a token: a non-sensitive reference that maps back to the original credential inside the vault.
Because your own infrastructure never touches the PAN, it falls outside the most demanding PCI DSS requirements. The result is a dramatically reduced compliance scope – typically from SAQ D (hundreds of controls) to SAQ A (a short self-assessment).
→ Hellgate Guardian handles PCI vaulting for enterprise merchants · Full guide: Credit Card Vault
Label








