02 Where the funds are
Not with us.
This is the most important point on this page, and the most widely misunderstood in the industry.
Safeguarding
Customer balances are held in segregated safeguarding accounts at the issuing electronic money institution, separate from our own funds. If BuyVirtualCards ceased trading tomorrow, those funds would not be part of our assets: they would remain yours.
We do not custody your crypto-assets
A top-up is converted on receipt. There is no BuyVirtualCards wallet where customers' bitcoin sits, and therefore no concentration of funds to steal. The best way not to have a treasure stolen is not to build one.
No market exposure
Your balance is denominated in electronic money. A fall in bitcoin after your top-up does not touch it. Equally, a rise does not benefit you: this is not an investment product, and we do not pretend otherwise.
03 Your account
Mandatory second factor
Authenticator app (TOTP) or a physical security key (WebAuthn). SMS is not offered as a sole factor: SIM swapping is too common to pretend otherwise.
Passwords hashed with scrypt
OWASP-aligned parameters, a random salt per account, constant-time comparison. We cannot read your password, and nobody here can.
Signed sessions
HttpOnly cookie, SameSite=Lax, Secure in production, signed with HMAC-SHA256. Unreachable from page JavaScript, therefore out of reach of a script injection.
Alerts on sensitive events
Login from an unknown device, password change, adding a bank account: each triggers an email with an immediate lock link.
04 Card data
We do not store your number.
The full number, expiry date and security code are held by the issuing institution in its PCI-DSS certified environment. When you display them in your account they are fetched on the fly and rendered in an isolated frame: they never pass through our application servers and are never written to our logs.
What we keep: the last four digits, the network, the expiry date, and the card's state. Enough to show it in a list, not enough to pay with.
What each party sees
- BuyVirtualCards
- Balance, transaction log, last four digits of each card.
- Issuing institution
- Full card data, in a PCI-DSS environment. That is its job and its regulatory responsibility.
- Payment processor
- The invoice amount and the deposit address. No card data, no access to your balance.
- The merchant
- What any card passes on during a payment. On a single-use card, a number that will never work twice.
05 Report a vulnerability
Responsible disclosure
If you find a vulnerability, write to [email protected]. We acknowledge within 48 hours and keep the researcher informed until it is fixed. We do not pursue researchers who respect the rules opposite. Please allow us 90 days before publishing.
The rules
- Test only on your own accounts
- No denial-of-service attacks
- No access to or exfiltration of anyone else's data
- No social engineering of our staff or customers
- Stop as soon as a flaw is confirmed, and report it
06 Be sceptical, including of us
How to spot a scam.
The crypto-to-card space attracts a lot of fraudsters. Here are the signals that should make you walk away — apply them to us too.
Nobody can issue a card in the name of a bank it does not act for. A site offering to "generate" a Revolut, BNP Paribas or Bank of America card on demand is lying about what it sells. You will pay in crypto, with no recourse, and receive nothing usable.
A serious payment service names the institution that issues its cards and publishes its licence number. If that information cannot be found, there is no institution behind it.
Customer counters that climb on their own, glowing reviews all posted the same week, press logos with no article behind them, "since 2018" on a domain registered three months ago. These signals take an hour to fabricate and exist solely to borrow trust that was never earned. Check a domain's age with a whois lookup.
We will never contact you first on Telegram, WhatsApp or Discord, and we will never ask for your password, a one-time code, or a payment to "unlock" your account. Any such request is fraud, whatever name the sender displays.