Skip to main content
Home · Quality

Quality, security and compliance

In our field a non-conformity is not a production defect: it is a card rejected by a payment scheme, a passport that will not read at a border, or citizen data exposed. Compliance is not a side service at Alty, it is the condition of doing business.

01

Our quality policy

  • Only offer products from certified and audited production lines
  • Have every payment application validated by the relevant scheme before any deployment
  • Keep production, personalisation and test environments strictly separated
  • Trace every batch, every card and every key from manufacture to client handover
  • Document operating procedures and hand them to the client rather than keeping them
  • Announce a timeline we can hold rather than a commercial one
02

Certifications and standards

The certifications below apply to the industrial chains, card operating systems and platforms we mobilise for our clients. The corresponding attestations are provided within tender submissions, on request.

Payment

EMVCoCompliance of applications and cards with EMV contact and contactless specifications
VisaApproval of personalisation lines and payment applications
MastercardApproval of personalisation lines and payment applications
PCI DSSSecurity of cardholder data processing environments

Telecom

GSMA SAS-UPSecurity of SIM card production and personalisation sites
GSMA SAS-SMSecurity of eSIM remote provisioning platforms

Identity

ICAO 9303Compliance of machine-readable travel documents
MOSIPCompatibility with the open digital identity platform

System

ISO 9001Quality management system
ISO/IEC 27001Information security management system

Product

Common Criteria EALSecurity evaluation of components and operating systems
GlobalPlatformInteroperability and secure management of embedded applications
03

Chain of control

01

Selection

No component, chip or operating system enters an offer without verified certification and a supporting attestation.

02

Qualification

Every configuration is qualified on samples before series launch: reading, personalisation, durability, field compatibility.

03

Controlled production

Manufacturing on a certified site, with batch traceability, counting and controlled destruction of rejects.

04

Secure personalisation

Separated environment, key management under ceremony, full logging of access and data flows.

05

Acceptance and audit

Joint acceptance testing with the client, sampling, and compliance audit for the life of the contract.

04

Data protection

The data we process on behalf of our clients — identities, fingerprints, banking data — remains the client's property. It is processed in separated environments, encrypted at rest and in transit, and hosted on national territory where the regulatory framework or the specification requires it. We retain no data beyond the contractual period and always hand over the erasure procedures.

A card, SIM or identity document project?

Describe your specification. We answer with a technical analysis and a realistic timeline.