GUARDIAN

Take control of your authorization rates

Guardian gives you the tokenized foundation to route intelligently, detect fraud natively, and monitor every transaction in real time.

THE PROBLEM

Your single-PSP setup has a ceiling.

When one provider handles everything, you lose the granular control that separates good payment operations from great ones.

No acquirer competition

Proprietary tokens lock your volume to a
single processor. You can't A/B test
acquirers or leverage competitive pressure
to lower fees.

Proprietary tokens lock your volume to a single processor. You can't A/B test acquirers or leverage competitive pressure to lower fees.

Blind optimization

Without independent observability, you rely
on your PSP's self-reported metrics. No
way to verify auth rates, identify anomalies,
or benchmark performance.

Without independent observability, you rely
on your PSP's self-reported metrics. No way to verify auth rates, identify anomalies, or benchmark performance.

Fragmented fraud stack

Adding third-party fraud engines means
complex integrations that expose raw card
data, expanding your PCI scope and
slowing your checkout.

Adding third-party fraud engines means complex integrations that expose raw card data, expanding your PCI scope and slowing your checkout.

Composable Payment Architecture

Four modules. Total control.

Guardian is the tokenized foundation.

Compose it with Hub, Specter, and Pulse to build a payment stack optimized for your KPIs.

Guardian

Vault & Tokenization

Hub

Smart Routing

Specter

Fraud Intelligence

Pulse

Observability

Each module works independently or together. Start with Guardian for

tokenization, then compose Hub, Specter, and Pulse as your needs grow.

See how Guardian can transform your payment operations.

Capabilities

Every lever. One platform.

Guardian combined with the CPA gives you the tools to optimize authorization rates, reduce fraud, and monitor everything.

Multi-acquirer routing

With vendor-independent tokens, route transactions to the best-
performing acquirer by region, card type, or cost. Small
improvements in auth rates translate to significant revenue at scale.

With vendor-independent tokens, route transactions to the best-performing acquirer by region, card type, or cost. Small improvements in auth rates translate to significant revenue at scale.

Routing decision tree illustration

Native fraud scoring

Specter integrates natively with Visa Decision Manager, passing
transaction telemetry for real-time risk scoring. Reduce chargebacks
without exposing raw data or adding checkout latency.

Specter integrates natively with Visa Decision Manager, passing transaction telemetry for real-time risk scoring. Reduce chargebacks without exposing raw data or adding checkout latency.

Routing decision tree illustration

Real-time payment observability

Pulse streams events across your entire payment flow. Surface
anomalies, track auth rates by acquirer, and generate executive-level
insights without third-party analytics tools.

Pulse streams events across your entire payment flow. Surface anomalies, track auth rates by acquirer, and generate executive-level insights without third-party analytics tools.

97.3%

Auth rate

0.12%

Chargeback Rate

23ms

Median latency

Network Token lifecycle

Dynamic cryptograms from Visa and Mastercard boost issuer trust. Account Updater automatically refreshes expiring credentials, protecting subscription revenue from silent churn.

True data sovereignty

Universal tokens belong to you. Route to any acquirer, threaten
migration credibly, and force PSPs to compete on price. Your vault,
your leverage.

Universal tokens belong to you. Route to any acquirer, threaten migration credibly, and force PSPs to compete on price. Your vault,
your leverage.

Use Cases

Built for your payment challenges.

Guardian serves as the secure foundation for the payment operations that matter most to your business.

Multi-acquirer routing

Optimize globally by routing to the best acquirer per market.

Route by region, BIN, card type

Failover between processors

A/B test acquirer performance

Subscription protection

Eliminate involuntary churn from expiring card credentials.

Auto-refresh via Account Updater

Network Token lifecycle

Zero customer intervention

Marketplace payments

Secure multi-party payment flows for complex marketplace models.

Tokenize across sellers

PCI descoping for platform

Route per-seller to optimal PSP

Trusted by enterprise payment teams

"By moving to Guardian's token vault,

we finally took back control of our customers' payment credentials.

We're now able to keep cards on file automatically updated behind the scenes,

and we have the total freedom to steer our

payment flows directly to our preferred gateways."

Head of Payments
at a high-volume European merchant

OPERATIONAL COMPARISON

More control. Better outcomes.

How Guardian and Hellgate Cloud Platform compares to monolithic PSPs on the KPIs that drive your payment strategy.

Operational Factor

Monolithic PSP

Hellgate Guardian

Acquirer routing

Single processor. No ability to A/B test or failover between acquirers.

Route by region, BIN, card type, or cost. Automatic failover via Hub orchestration.

Auth rate optimization

Dependent on PSP's internal optimization. No independent benchmarking.

Network Tokens with dynamic cryptograms increase issuer trust. Account Updater prevents silent declines.

Fraud intelligence

Bundled fraud tools. Limited to what the PSP offers. Adding external engines expands PCI scope.

Native Specter integration with Visa Decision Manager. Real-time scoring without exposing raw data.

Payment observability

PSP-reported dashboards. No independent event streaming or anomaly detection.

Pulse streams real-time events across the full flow. Independent anomaly detection and performance tracking.

Vendor independence

Proprietary tokens. Migration requires customer re-entry of card details.

Universal tokens belong to you. Move volume to any acquirer without customer intervention.

Credential lifecycle

Basic updater services. Inconsistent coverage across card networks.

Visa + Mastercard Account Updater with automatic fallback from Network Tokens to vault tokens.

"Monolithic PSP" reflects common limitations of bundled payment platforms. Hellgate CPA capabilities per developer.hellgate.io

AGENTIC COMMERCE READY

When agents start transacting, your controls still apply.

AI-initiated payments flow through the same Guardian vault, Hub routing, Specter fraud scoring, and Pulse observability as human-initiated transactions. No control gaps.

Side-by-side flow comparison: human checkout and AI
agent both converging into the same CPA pipeline
(Guardian > Hub > Specter > Pulse). Identical controls,
different initiation point.

Today

Human commerce

Guardian vaults credentials from browser
checkouts. Hub routes. Specter scores. Pulse
monitors. Your full stack is operational.

With vendor-independent tokens, route transactions to the best-performing acquirer by region, card type, or cost. Small improvements in auth rates translate to significant revenue at scale.

Emerging

Hybrid flows

AI assistants help humans complete purchases. Guardian's tokens are already accessible via API, so agent-assisted flows work without changes.

With vendor-independent tokens, route transactions to the best-performing acquirer by region, card type, or cost. Small improvements in auth rates translate to significant revenue at scale.

Next

Autonomous agents

AI agents initiate M2M purchases with no human in the loop. Guardian serves as the secure token wallet. Same routing, fraud, and observability rules apply.

With vendor-independent tokens, route transactions to the best-performing acquirer by region, card type, or cost. Small improvements in auth rates translate to significant revenue at scale.

Routing rules persist

Agent transactions follow the same Hub routing logic. Cost-based, region-based, and performance-based rules apply automatically.

Fraud controls hold

Specter scores every transaction identically, regardless of whether a human or agent initiated it. No gaps in fraud coverage.

Full observability

Pulse streams agent-initiated events into the same dashboards. Track auth rates, anomalies, and performance across all transaction types.

See Guardian in action.

See Guardian in action.

Walk through Hellgate Cloud Platform with our product team.
We'll map Guardian to your payment stack and
show you exactly where it drives impact.

PRICING

Scale on your terms

Our usage-based pricing is built for growth
- with no hidden fees, no surprises, and no friction.

Playground

0.28 EUR

per hour

5000 tokens

Development Tier

SAQ/A, A-EP, D

Single node

EU region only

Network Token support

DAuth Support

DEV

Hello World

0.56 EUR

per hour

Unlimited Tokens

Production Tier

SAQ/A

Single node

EU region only

S

Go Live

1,000 EUR

per month

Everything in "Hello World" Plan

Cluster M

EU and US region

Network Token support ¹

M

Think Global

5,800 EUR

per month

Everything in "Go Live" Plan

SAQ/A, D

Cluster L

All regions

Network Token support ²

L

Think Big

12,500 EUR

per month

Everything in "Think Global" plan

SAQ/A, D, RoC

Cluster XL

High Availability

Network Token support 3

XL

God Mode

Contact us


Everything in "Think Big" Plan

Cluster XXL

DAuth Support

Extension Support

Network Token support 4

XXL

1 Max 1,000k Network Tokens

1 Max 1,000k Network Tokens

1 Max 1.000k Network Tokens

2 Max 10,000k Network Tokens

2 Max 10.000k Network Tokens

3 Max 25,000k Network Tokens

3 Max 25.000k Network Tokens

3 Max 25.000k Network Tokens

4 Sky is the limit

4 Sky is the limit

ADD-ONS

Add-on Services

Enabling efficient orchestration, expanding merchant access, and powering embedded finance models.

Network Tokens

Manages lifecycle of network tokens (Visa, Mastercard, etc.)

Enables secure token provisioning and refreshing

Enables processing over different PSPs and Acquirers

Optional fallback for PAN vaulting

Build modern, user-friendly authentication flows aligned with PSD2 and beyond with delegated authentication

Account Updater

Keeps stored CHD actual and refreshes if needed

Reduces transaction failures through expired, replaced, reissued CHD

Is integrated with VISA (Account Updater) and Mastercard (Automatic Billing Updater)

Improves authorization rates

Improves customer retention, esp. for loyalty programs and recurring billings

Identification and Verification for Tokens

Fully compliant with EMV 3DS 2.x protocol

Supports both frictionless and challenge flows

Designed for seamless use across multiple PSPs and Acquirers

Compatible with PSD2/SCA and global authentication mandates

Card Metadata Service

Provides Card Metadata, like Issuer, BIN, and country

Delivers card types, scheme affiliation and feature flags

Provides the fuel to improve routing scenarios and customer analytics

FAQ

FAQ

FAQ

What is Hellgate Guardian?

Guardian is Hellgate's fully PCI-compliant tokenization service, delivered as managed, dedicated infrastructure. It sits as a protective yet actionable layer between your services and the sensitive data it stores – primarily card credentials – replacing raw data with tokens your systems can safely handle.

By taking sensitive data out of scope, Guardian unlocks composability: you can combine payment services freely without each one dragging PCI scope, compliance, and data-protection obligations along with it.

→ Explore Guardian

Label

Can Guardian be used standalone?

Yes. Guardian is a standalone CPA component, fully independent of Hub or Commerce. Many organisations adopt Guardian on its own purely to cut PCI scope – vaulting card data with Hellgate while keeping their existing payment stack – and compose other services later if they choose.

It also works naturally alongside other Hellgate services: Specter, for example, can read token-level signals from Guardian to sharpen fraud scoring.

→ Use Guardian standalone

Label

How does Guardian reduce PCI DSS scope?

When you route card data through Guardian, the data lives entirely inside a PCI DSS Level 1 certified cardholder data environment operated by Hellgate – not in your own infrastructure. Your systems only ever handle non-sensitive tokens.

Because your environment never touches the PAN, it falls outside the most demanding PCI requirements. In practice this often moves a merchant from SAQ D (hundreds of controls) to a far lighter SAQ A or SAQ A-EP self-assessment.

→ See Hellgate's Trustcenter

Label

What is a credit card vault and how does it work?

A credit card vault is a PCI DSS-certified environment that stores cardholder data – primarily Primary Account Numbers (PANs) – on behalf of a merchant. Instead of storing raw card data yourself, you store a token: a non-sensitive reference that maps back to the original credential inside the vault.

Because your infrastructure never holds the PAN, it falls outside the most demanding PCI controls, dramatically reducing your compliance burden while you still transact normally using the token.

→ Guardian handles PCI vaulting for enterprise merchants

Label

Does Guardian only handle card data?

Cards are the primary use case, but Guardian is not limited to them. Alongside PCI tokens for payment credentials, it offers generic tokens that store arbitrary sensitive payloads – for example SEPA bank details, API keys, or personally identifiable information (PII).

That makes Guardian useful for GDPR-driven data-protection needs as well as PCI: any sensitive value your systems shouldn't hold in the clear can be vaulted and referenced by token.

→ See generic tokens

Label

What token types does Guardian support?

Guardian supports four token types. PCI tokens (standard) protect card credentials and keep raw PANs out of your systems. Generic tokens (standard) store arbitrary sensitive payloads such as SEPA credentials or PII. Network tokens (add-on) are scheme-issued tokens for higher authorization and lower fraud. Metadata inquiries (add-on) return card and issuing-bank data for display, validation, routing, and analytics.

Add-on features are enabled per account through your Hellgate representative.

→ Compare Guardian token types

Label

How do network tokens improve authorization rates?

Network tokens replace the card PAN with a scheme-issued token that the card networks keep continuously updated. When a customer's card is reissued or its expiry changes, the token still works – so recurring and subscription payments don't fail at renewal.

Because they carry richer, verified data and reduce reliance on static PANs, network tokens typically lift authorization rates, reduce declines, and mitigate fraud. Guardian can provision them from a session, PAN, or existing PCI token.

→ Learn about network tokens

Label

Can I migrate existing tokens into Guardian?

Yes. Guardian supports both PCI token import and export, so you can migrate stored credentials from another vault into Guardian – and move them out again if you ever need to. Migration flows are documented and designed to run without disrupting live transactions.

Portable tokens are a deliberate anti-lock-in feature: your data stays yours, which is central to the CPA philosophy.

→ See token migration

Label

Is Guardian delivered on dedicated infrastructure?

Yes. Guardian is delivered as managed, dedicated single-tenant infrastructure: your instance is provisioned exclusively for your organisation, with compute, storage, and network never shared with other clients. Your payment data is physically isolated, with no possibility of cross-tenant access.

Hellgate operates and manages the infrastructure on your behalf, but full data ownership stays with you – and you can choose an Azure region close to your workloads for latency and data-residency reasons.

→ Getting access to Guardian

Label

How does Guardian support PCI DSS v4.0 compliance?

Guardian is operated as a PCI DSS Level 1 certified service. When you route card data through it, that data lives entirely within Hellgate's certified cardholder data environment rather than your own infrastructure, so you can significantly reduce your PCI scope and often qualify for lighter self-assessment questionnaires (SAQ A or SAQ A-EP).

Guardian also supports v4.0 requirements such as customised implementation of multi-factor authentication and encrypted data transmission.

→ Hellgate Trustcenter

Label

What are metadata inquiries and why do they matter?

Metadata inquiries let you retrieve comprehensive card and issuing-bank information from a PAN, a PCI token, or a network token – without exposing the underlying sensitive data. Typical uses include displaying card brand and last four digits, validating a card, making routing decisions (for example, sending a transaction to the acquirer with the best rate for that issuer), and enriching analytics.

It's an add-on feature that turns vaulted data into actionable signal while keeping it protected.

→ See metadata inquiries

Label

Does Guardian help with GDPR and PII data protection?

Yes. Beyond cards, Guardian's generic tokens can vault other categories of sensitive and personally identifiable information, so PII never sits in the clear in your own systems. Combined with dedicated, single-tenant infrastructure and your choice of Azure region for data residency, this supports GDPR obligations around data minimisation, protection, and locality.

You keep full ownership of the data, while Guardian provides the certified environment that holds it.

→ How Guardian protects sensitive data

Label

How does forwarding sensitive data work without touching my systems?

Guardian's forwarding lets you send card data to a certified third-party provider without that data ever passing through your infrastructure. You reference a token; Guardian injects the sensitive value (card data, or a network-token cryptogram) into the outbound request server-side, then forwards it.

This is how SAQ-A merchants can, for example, use network tokens or connect to a new processor without ever handling a raw PAN or cryptogram themselves.

→ See secure forwarding

Label

What is a credit card vault and how does it reduce PCI scope?

A credit card vault is a PCI DSS-certified environment that stores cardholder data – primarily Primary Account Numbers (PANs) – on behalf of a merchant. Instead of storing raw card data in your own systems, you store a token: a non-sensitive reference that maps back to the original credential inside the vault.

Because your own infrastructure never touches the PAN, it falls outside the most demanding PCI DSS requirements. The result is a dramatically reduced compliance scope – typically from SAQ D (hundreds of controls) to SAQ A (a short self-assessment).

→ Hellgate Guardian handles PCI vaulting for enterprise merchants · Full guide: Credit Card Vault

Label

BOOK A DEMO

See Guardian in action.

See Guardian in action.

See Guardian in action.

Walk through the Hellgate Cloud Platform with our product team. We'll map Guardian to your payment stack and show you exactly

where it drives impact.

Deep dive into your current payment infrastructure challenges

Deep dive into your current payment infrastructure challenges

Personalized walkthrough of relevant Hellgate features for your use case

Personalized walkthrough of relevant Hellgate features for your use case

Clear explanation of implementation and integration paths

Clear explanation of implementation and integration paths

Live Q&A with our payment specialists

Live Q&A with our payment specialists

Book a demo with our product specialists

Book a demo with our product specialists

Trusted by enterprise clients

Trusted by enterprise clients