Skip to content
TRUST CENTER

Bank-grade by default.
Audited continuously.

Rigid moves cardholder money and cardholder data. Both are protected by controls that are tested by auditors, attacked by red teams, and published here.

PCI DSS

Level 1 Service Provider

SOC 2

Type II · annual

ISO 27001

Certified

GDPR

DPA available

DORA

EU operational resilience

99.999%

Uptime SLA · enterprise

DATA

Encryption everywhere

AES-256 at rest, TLS 1.3 in flight, PANs tokenized with hardware-backed HSM key management. Card data never touches your systems unless you ask it to.

RESIDENCY

Data stays in region

Edge authorization is global; data residency is regional. Cardholder data pinned to EU, UK, US, APAC or LATAM regions per programme.

ACCESS

SSO, roles & audit

SAML & OIDC SSO with SCIM provisioning, least-privilege roles per workspace, and an immutable audit log of every human and API action.

RESILIENCE

Built to keep authorizing

Active-active across regions with stand-in processing — if a region degrades, auths keep flowing at the next-nearest edge.

TESTING

Attacked on purpose

Continuous automated scanning, quarterly external pentests, an always-on bug bounty, and chaos drills against the auth path itself.

TRANSPARENCY

Reports on request

SOC 2 report, pentest summaries, subprocessor list and uptime history — available under NDA from this page, not after three sales calls.

All systems operational
AUTH API · 100%LEDGER · 100%KYC · 100%WEBHOOKS · 99.99%
status.rigid.fi →

Send this page to your auditors.

SOC 2 report, DPA and subprocessor list — request access and we'll share under NDA today.