Trust

Security

What protects an account, what protects a card, and what we ask you to do. Written to be checked, not admired.

Account security

Two-factor authentication

Time-based one-time codes as a second factor on login and on sensitive actions, so a compromised password alone is not enough.

Biometric login

Fingerprint and face recognition on supported devices, backed by the device's own secure enclave rather than a stored biometric template.

Device management

A list of authorised devices with the ability to review and revoke any of them, so a lost phone stops being a live session.

Real-time alerts

Notifications on login from a new device, on card authorisations, and on account changes, so anomalies are visible immediately rather than at statement time.

Card security

Instant freeze

Suspend a card immediately from the app without reissuing it, and reinstate it just as fast when the card turns up in a coat pocket.

Spending controls

Per-card limits and merchant category restrictions applied at authorisation, so a card can only be used where you intend it to be used.

Tokenisation

Virtual cards are tokenisation-ready for mobile wallets, so the underlying card number is not exposed to the merchant.

Transaction monitoring

Rule-based screening and anomaly detection at authorisation, with alerting configured to the issuing institution's policy.

What we ask of you

Use a unique password that you do not use anywhere else, and enable two-factor authentication. Review your authorised devices periodically and revoke any you do not recognise. Treat any message asking for your password, one-time code or full card number as fraudulent, regardless of who it claims to be from.

We will never ask for these
Zen Card staff will never ask for your password, your two-factor code, your PIN, or your full card number, by email, phone, chat or any other channel. If someone does, they are not us.

Responsible disclosure

If you believe you have found a security vulnerability, report it to info@otaropay.com with enough detail to reproduce the issue. Please give us a reasonable window to investigate and remediate before disclosing publicly, and do not access, modify or exfiltrate data belonging to other users while testing.

We will acknowledge reports, keep you updated on remediation, and credit researchers who ask to be credited.

Certifications and audit
Independent security certifications and audit reports are a documented gap in the current build. Institutions conducting vendor due diligence should request the current control documentation directly; published attestations will be listed here as they are obtained.

Security questions from a diligence team?

We will provide the control documentation, data-processing terms and responsibility matrix on request.

Zen CardZen Card

Crypto-funded cards on the Visa network, and the white-label issuing platform behind them.

Corporate information. This website is operated by Otaro Pay Ltd, FINTRAC M23150730, Suite 250 - #1585 997 Seymour St, Vancouver BC V6B 3M1. Contact: info@otaropay.com.

Regulatory notice. Otaro Pay Ltd is a FINTRAC MSB. It is not a bank and does not itself issue cards, take deposits, extend credit or provide investment services. Cards, accounts, credit and yield-bearing products described on this site are provided by licensed financial institutions, subject to their terms, their approval, and the regulations of the relevant jurisdiction. Availability varies by country. Digital assets are volatile and capital is at risk. Nothing on this website constitutes an offer, a solicitation, financial advice or investment advice.

© 2026 Otaro Pay. All rights reserved.

Launch App →