Skip to content
Trust & compliance

The certifications behind every card you issue.

Virtual Card Maker runs on Zil Money’s payment infrastructure. Here is what that infrastructure is certified, audited, and aligned against, item by item, and what each one actually covers.

Independently audited and certified

9 standards, held at the platform level.

  • PCI DSS aligned
  • ISO 9001 Quality Management Certified
  • ISO 20000 IT Service Management Certified
  • ISO 27001 Information Security Management Certified
  • Aligned with NIST SP 800-53 controls
  • AICPA SOC for Service Organizations
  • AICPA SOC Service Organization Control Reports
  • HIPAA-aligned safeguards
  • CCPA requirements followed
Certifications

Nine standards, one platform.

Virtual Card Maker is a service of Zil Money. The standards here are maintained at the Zil Money platform level, the same infrastructure that issues, processes, and settles every card on Virtual Card Maker. Card issuance, processing, and settlement happen through Zil Money’s licensed banking partners.

Each item covers a different part of how the platform is built, run, and reviewed: some are third-party certifications, some are independent auditor attestations, some are framework alignments. Here is what each one actually means, in plain terms.

  • PCI DSS alignedStandard alignment

    PCI DSS

    Card processing aligns with the Payment Card Industry Data Security Standard, the baseline for any company that accepts, processes, stores, or transmits card data. That means strong access controls, secure networks, and encrypted transmission and storage of cardholder data.

    Applies to: Card issuance and transaction processing on Virtual Card Maker.

  • ISO 9001 Quality Management CertifiedCertification

    ISO 9001

    Zil Money’s quality management system is ISO 9001 certified, the international standard for consistent service delivery, documented processes, and continuous improvement.

    Applies to: Zil Money’s products and services, including Virtual Card Maker.

  • ISO 20000 IT Service Management CertifiedCertification

    ISO 20000

    Zil Money’s IT service management is ISO 20000 certified, the international standard for reliable, well-managed delivery of IT services, including how incidents and changes are handled.

    Applies to: The IT service management behind the platform.

  • ISO 27001 Information Security Management CertifiedCertification

    ISO 27001

    Zil Money’s information security management system is ISO 27001 certified, the international standard for identifying, managing, and reducing risk to sensitive information.

    Applies to: Zil Money’s internal systems and customer-facing services.

  • Aligned with NIST SP 800-53 controlsFramework alignment

    NIST SP 800-53

    Security controls are aligned with NIST SP 800-53, the federal framework for protecting information systems. It is a control framework rather than a pass/fail certification, and is commonly required in government and enterprise vendor reviews.

    Applies to: Government and enterprise vendor due diligence.

  • AICPA SOC for Service OrganizationsIndependent audit

    SOC 1, Type 1

    An independent auditor’s report on the controls behind financial transaction processing — the checks that confirm money moves the way it is supposed to and gets recorded correctly. The current report is a Type 1 engagement, a point-in-time assessment of control design.

    Applies to: Financial transaction processing on the Zil Money platform.

  • AICPA SOC Service Organization Control ReportsIndependent audit

    SOC 2, Type 1

    Evaluates controls against the AICPA Trust Services Criteria for security, availability, and confidentiality: how systems are protected from unauthorized access, kept running, and how sensitive data is restricted to authorized users. The current report is a Type 1 engagement, a point-in-time assessment of control design.

    Applies to: The infrastructure Virtual Card Maker runs on.

  • HIPAA-aligned safeguardsSafeguard alignment

    HIPAA

    Zil Money’s underlying platform infrastructure maintains safeguards aligned with HIPAA’s security requirements. Virtual card issuance itself does not involve processing protected health information; this reflects the security bar the infrastructure is held to, not a healthcare-specific service.

    Applies to: Platform infrastructure alignment, inherited from Zil Money.

  • CCPA requirements followedRegulation

    CCPA

    Follows California Consumer Privacy Act requirements, as amended by the CPRA, giving California residents the right to know what personal data is collected, request its deletion, opt out of its sale or sharing, and limit use of sensitive personal information.

    Applies to: All Virtual Card Maker users who are California residents.

FAQ

Common questions.

Virtual Card Maker is a service of Zil Money. These certifications and standards are maintained at the Zil Money platform level, the same infrastructure that issues, processes, and settles every Virtual Card Maker transaction.

SOC engagements and ISO certifications are each conducted by independent third-party auditors rather than self-assessed.

Running a vendor review? Tell us which documents your process needs and we will point you at what is available.

Talk to the team

VirtualCardMaker.com, powered by Zil Money, is a financial technology company, not a bank. Banking and money movement services are provided through partner financial institutions and licensed service providers. FDIC insurance coverage applies only to eligible deposit products and accounts, and is subject to applicable terms, conditions, limitations, and requirements. Additional information regarding partner institutions, products, and services is available in the applicable terms and agreements.

Issued on infrastructure that is audited.

A Visa card per vendor, per hire, per trip, on a platform held to nine independent standards.