English

Select Language

Bin Search Lookup

Security & Compliance

BINSearchLookup encrypts all traffic, operates under SOC Type I & II monitoring, implements post-quantum cryptography, and undergoes annual third-party security audits.

PCI DSS Compliant SOC Type I & II TLS 1.3 Post-Quantum (ML-KEM) GDPR · PIPEDA · CCPA

What data we handle

BINSearchLookup processes only the first 6–8 digits of payment card numbers — the BIN or IIN prefix. Under PCI DSS, these digits are not classified as sensitive cardholder data. We never receive, store, or transmit full card numbers, CVV codes, expiry dates, or cardholder names.

BIN lookup is 100% outside PCI DSS cardholder data scope. Integrating our API does not expand your PCI DSS scope.

Traffic encryption

All traffic between clients and BINSearchLookup infrastructure is encrypted end-to-end:

Post-quantum cryptography (PQC)

BINSearchLookup has deployed post-quantum cryptography to protect against future quantum computing threats on sensitive infrastructure channels:

SOC monitoring

Our infrastructure operates under continuous SOC (Security Operations Center) monitoring:

Security audits

BINSearchLookup undergoes regular third-party security assessments:

PCI DSS scope

BINSearchLookup subscription payments are processed by Stripe, Inc. (PCI DSS Level 1 certified). We do not store your payment card details. All billing data is held exclusively by Stripe.

Because BINSearchLookup handles only the non-sensitive BIN prefix (not cardholder data), our API integration does not require merchants to expand their PCI DSS cardholder data environment.

Data retention

Privacy compliance

We comply with GDPR (EU), PIPEDA (Canada), and CCPA (California). See our Privacy Policy for full details on data handling, retention, and your rights.

Responsible disclosure

If you discover a security vulnerability, please contact us privately before public disclosure:

[email protected]

We aim to respond within 5 business days. We do not pursue legal action against good-faith security researchers acting within a responsible disclosure framework.