Quality, security and compliance
In our field a non-conformity is not a production defect: it is a card rejected by a payment scheme, a passport that will not read at a border, or citizen data exposed. Compliance is not a side service at Alty, it is the condition of doing business.
Our quality policy
- Only offer products from certified and audited production lines
- Have every payment application validated by the relevant scheme before any deployment
- Keep production, personalisation and test environments strictly separated
- Trace every batch, every card and every key from manufacture to client handover
- Document operating procedures and hand them to the client rather than keeping them
- Announce a timeline we can hold rather than a commercial one
Certifications and standards
The certifications below apply to the industrial chains, card operating systems and platforms we mobilise for our clients. The corresponding attestations are provided within tender submissions, on request.
Payment
| EMVCo | Compliance of applications and cards with EMV contact and contactless specifications |
| Visa | Approval of personalisation lines and payment applications |
| Mastercard | Approval of personalisation lines and payment applications |
| PCI DSS | Security of cardholder data processing environments |
Telecom
| GSMA SAS-UP | Security of SIM card production and personalisation sites |
| GSMA SAS-SM | Security of eSIM remote provisioning platforms |
Identity
| ICAO 9303 | Compliance of machine-readable travel documents |
| MOSIP | Compatibility with the open digital identity platform |
System
| ISO 9001 | Quality management system |
| ISO/IEC 27001 | Information security management system |
Product
| Common Criteria EAL | Security evaluation of components and operating systems |
| GlobalPlatform | Interoperability and secure management of embedded applications |
Chain of control
Selection
No component, chip or operating system enters an offer without verified certification and a supporting attestation.
Qualification
Every configuration is qualified on samples before series launch: reading, personalisation, durability, field compatibility.
Controlled production
Manufacturing on a certified site, with batch traceability, counting and controlled destruction of rejects.
Secure personalisation
Separated environment, key management under ceremony, full logging of access and data flows.
Acceptance and audit
Joint acceptance testing with the client, sampling, and compliance audit for the life of the contract.
Data protection
The data we process on behalf of our clients — identities, fingerprints, banking data — remains the client's property. It is processed in separated environments, encrypted at rest and in transit, and hosted on national territory where the regulatory framework or the specification requires it. We retain no data beyond the contractual period and always hand over the erasure procedures.
A card, SIM or identity document project?
Describe your specification. We answer with a technical analysis and a realistic timeline.