TapInfo/Trust Centre
The NFC card you can trust, and check.
Most NFC cards store a direct link that works forever, for whoever holds the card. TapInfo was designed the other way round: the chip holds a random ID, every tap passes through a resolver, and you decide what happens next. This page shows every control, its value, and where that value comes from.
Seven principles
Your identity is yours
You can export it, move it or delete it. A card is something you hold; the identity behind it belongs to you, and to your organisation only for work credentials it issued.
The chip holds a link, nothing personal
A TapInfo chip stores a short tapinfo.io address with a random ID. No name, number or email is written to the card, so a lost card gives away nothing on its own.
Every tap can be stopped at the source
Taps pass through the TapInfo resolver. That’s what lets any card be suspended, replaced or revoked without touching the card itself.
Nothing is shared without a tap
Your profile shows what you choose. People who tap see that, and nothing more. We never sell data and we don’t run ad tracking.
Organisations control credentials, not people
Admins can issue and revoke work cards and see how they’re used. They can’t read anyone’s private notes or personal profile fields.
We say what’s live
Every capability is listed with its real status. A feature in development is labelled as one, everywhere.
Problems are reported and fixed in the open
Security reports get a reply within two working days, and fixes are logged publicly once users are safe.
SAFE: the five layers
SAFE is TapInfo’s security framework. It covers everything between a card in someone’s hand and the data behind it, in five layers. Each layer lists its controls, the value we hold ourselves to, and the source of that value.
Credential
What’s physically on the card or tag, and what it can and can’t do.
| Control | Value | Source |
|---|---|---|
| Data written to the chip | One HTTPS link: tapinfo.io/c/ + random IDNo personal data on the card. | Product rule |
| Credential ID | 128-bit random, never sequentialIDs can’t be guessed or counted through. | Proposed |
| Chip write-lock | Locked permanently after encodingNobody can rewrite a TapInfo chip with a phone app. | Proposed |
| Clone resistance | Cryptographic chips (NTAG 424 DNA, SUN messages): each tap signs a one-time codeA copied card fails verification. | To confirm |
| Metal cards | Sealed NFC inlay on the back; the chip sits under it | Product rule |
Resolver
The service every tap passes through. This is where control lives.
| Control | Value | Source |
|---|---|---|
| Revocation takes effect | Under 60 seconds, worldwideMeasured from the admin action to the next tap. | Proposed |
| Suspend and reactivate | Instant, reversible, logged | Product rule |
| What a revoked card shows | A neutral notice. No name, no company, no history | Product rule |
| Transport security | HTTPS only, TLS 1.2+, HSTS preloaded | Proposed |
| Enumeration protection | Rate limits per IP and per ID; unknown IDs return the same page as revoked ones | Proposed |
| Availability target | 99.9% monthly, public status page | Proposed |
| Tap pages | Always served from tapinfo.io with a verified badgeA card that opens anywhere else isn’t a TapInfo card. | Commitment |
Identity
Your TapID and profile: who controls them and how they’re protected.
| Control | Value | Source |
|---|---|---|
| Persistence | TapID survives every credential change | Product rule |
| Field visibility | Show or hide each field; changes apply on the next tap | To confirm |
| Sign-in | Passkeys or email link plus two-factor; no SMS-only codes | Proposed |
| Session control | See and sign out every device | Proposed |
Organisation
What a company can do with the credentials it issues, and where that stops.
| Control | Value | Source |
|---|---|---|
| Roles | Owner, Admin, Member | Proposed |
| Offboarding | Revoke every credential a person holds in one action | Product rule |
| Reassignment | A returned card can resolve to a new person’s TapID | Product rule |
| Audit log | Every issue, replace, reassign, revoke and role change, with who and when; kept 24 months | Proposed |
| Admin visibility | Work profile and credential activity only. Never personal notes or personal fields | Commitment |
| Brand control | Approved designs only for team cards | To confirm |
Data
What we store, where, for how long, and how you get it back or remove it.
| Control | Value | Source |
|---|---|---|
| Encryption in transit | TLS 1.2+ everywhere | Proposed |
| Encryption at rest | AES-256 for databases and backups | To confirm |
| Hosting region | UK or EU | To confirm |
| Tap records kept | 24 months, then reduced to anonymous counts | Proposed |
| Export | Self-serve: JSON, CSV and vCard | Proposed |
| Account deletion | Live data within 30 days, backups within 35 | Proposed |
| Subject access requests | Answered within one month | UK law |
| Breach notification | To the ICO within 72 hours; to affected users without undue delay | UK law |
| Selling data or ad tracking | Never | Commitment |
Threats we design for
The most common NFC card stores a direct web link on an unlocked chip. Here is what happens with that design, and with TapInfo, when things go wrong.
| If… | A card with a direct link | A TapInfo card |
|---|---|---|
| You lose your card | Whoever finds it opens your profile, indefinitely. | Revoke it from your phone. The card shows a neutral notice from the next tap. |
| Someone leaves your company | Their card keeps pointing at their old profile or your company page. | An admin revokes or reassigns it. The relationships they made stay with you. |
| A card is copied | The copy works for as long as the original does. | Revoke the original ID and every copy dies with it. On cryptographic chips, copies fail from the start. |
| A chip is rewritten | Unlocked chips can be rewritten by any free phone app, sending taps to a stranger’s page. | TapInfo chips are write-locked when encoded. |
| A fake tag is planted | No way to tell a fake from a real one. | Real TapInfo taps always open on tapinfo.io with a verified badge, and anyone can check a card ID. |
| Someone tries to scrape profiles | Sequential or short IDs can be counted through. | Random 128-bit IDs and rate limits make guessing pointless. |
Ten questions to ask any NFC card provider
Use these to compare providers, including us. Each one links to our answer on this page.
- What exactly is written to the chip?Our answer →
- Can a lost card be switched off without the card in hand?Our answer →
- How long does revocation take to apply?Our answer →
- Can the chip be rewritten by someone else?Our answer →
- Can a card be copied, and what happens if it is?Our answer →
- When an employee leaves, who keeps the contacts they made?Our answer →
- Can admins read personal notes?Our answer →
- Where is data hosted, and for how long is it kept?Our answer →
- Can I export everything, in what formats, without asking?Our answer →
- Do you publish which features are live?Our answer →
Check a card
Every TapInfo card opens on tapinfo.io and shows its ID. Enter it here to see whether the card is genuine and active. If a card opens anywhere else, it isn’t a TapInfo card.
Try 7Q4M-R29X, K2PD-81VA or H7TW-3ZQE.
Preview Checks against sample IDs. On tapinfo.io this queries the live resolver and returns the same result a tap would.
Credential lifecycle
Every card and tag is in exactly one state. States are shown with a symbol and a word, never colour alone. Every change is logged.
| State | What a tap shows | Reversible |
|---|---|---|
| ACTIVE | The owner’s profile, with the fields they’ve chosen | — |
| SUSPENDED | A neutral “paused” notice. Nothing about the owner | Yes, instantly |
| REPLACED | The old card shows a neutral notice; the new card opens the same TapID | No; issue another card |
| REASSIGNED | The new holder’s profile. The previous holder’s data is never shown | By reassigning again |
| REVOKED | A neutral notice, identical to an unknown ID | No |
Organisation controls
When a company issues cards, it controls those cards. It doesn’t get access to its people’s private lives.
| Action | Owner | Admin | Member |
|---|---|---|---|
| Issue, replace and revoke work cards | ✓ | ✓ | — |
| Reassign a returned card | ✓ | ✓ | — |
| Offboard a person (revoke all their work cards) | ✓ | ✓ | — |
| Approve team card designs | ✓ | ✓ | — |
| See work card activity | ✓ | ✓ | — |
| Read audit log | ✓ | ✓ | — |
| Change roles and billing | ✓ | — | — |
| Edit own profile fields | ✓ | ✓ | ✓ |
| Read anyone else’s personal notes | — | — | — |
Proposed Role names and permissions are being finalised.
Security practice
How we build and run TapInfo, beyond the product controls above.
- Every code change is reviewed by a second person before release. Proposed
- Dependencies are scanned automatically and patched on a schedule; critical issues are patched within 7 days. Proposed
- Production access is limited to named people, uses hardware keys, and every access is logged. Proposed
- Secrets are kept in a managed vault and rotated; none live in code. Proposed
- Backups are encrypted, tested by restoring them, and kept for 35 days. Proposed
- This website sends strict security headers (HSTS, Content Security Policy, no third-party trackers) and publishes a security.txt file. Commitment
- Independent penetration test before general availability, with a summary published here. To confirm
We don’t claim certifications we don’t hold. When TapInfo is certified (for example Cyber Essentials or ISO 27001), the certificate will be linked here.
Privacy and your data
What we hold, why, for how long, and who can see it. The full legal text is in our privacy policy.
| What | Why | Kept for | Who can see it |
|---|---|---|---|
| Profile fields you publish | To show people who tap | Until you remove them | Anyone who taps, only the fields you choose |
| Account email and sign-in records | To sign you in and protect your account | Life of the account; sign-in logs 12 months Proposed | You |
| Tap records (time, card, approximate city) | So you can see activity | 24 months, then anonymous counts Proposed | You; admins for work cards |
| Relationship records and notes | Your memory of introductions | Until you delete them | You. Never admins |
| Details someone shares with you | So they can send you their details | Until you or they delete them | You |
| Orders and invoices | Tax and accounting | 6 years UK law | You; our finance team |
| Card payment details | Taking payment | Held by Shopify, our checkout provider | We never see full card numbers |
Your rights, in practice
- Export: download everything as JSON, CSV and vCard from your account, any time. Proposed
- Delete: close your account and live data is erased within 30 days, backups within 35. Proposed
- Ask: email [email protected] for a copy of your data. We reply within one month. UK law
- Complain: you can contact the Information Commissioner’s Office at ico.org.uk.
Data controller: Company legal name, ICO registration ICO registration number. Data is hosted in the UK or EU.
Subprocessors
Companies that process data for us. We give 30 days’ notice before adding one. Commitment
| Company | What for | Where |
|---|---|---|
| Hosting provider | Application hosting and database | Region |
| Email provider | Sign-in links and receipts | Region |
| Shopify | Checkout, card payments and orders. We never see full card numbers | Region |
| Print and fulfilment partner | Card and tag production | Region |
| Royal Mail | Delivery | United Kingdom |
Status and availability
The resolver is the one part of TapInfo that has to be up for a tap to work. We target 99.9% monthly availability and publish incidents with a timeline and cause. Proposed
Live status: status.tapinfo.io To confirm
If the resolver were ever unreachable, a tap shows the browser’s connection error. It never falls back to another site.
Report a vulnerability
If you find a security problem in TapInfo, its cards, or this website, tell us. We won’t take legal action against good-faith research that follows this policy.
- Where: [email protected]
- We reply within 2 working days, confirm or rule out the issue within 5, and agree a fix date with you. Commitment
- In scope: tapinfo.io and its subdomains, the TapInfo apps, the resolver, and TapInfo cards and tags.
- Please don’t: access other people’s data, run denial-of-service tests, or use social engineering.
- Credit: with your permission, we thank you by name here once the fix is out.
Machine-readable contact details are published at tapinfo.io/.well-known/security.txt.
What’s live
Every capability has one of five states: Available, Controlled rollout, In development, Direction, Not supported. Nothing is marked Available until it’s in customers’ hands.
| Capability | Status |
|---|---|
| TapID persistent identity | Awaiting confirmation |
| NFC cards with activation | Awaiting confirmation |
| Tap Tags | Awaiting confirmation |
| Suspend, replace and revoke | Awaiting confirmation |
| Reassign to a new person | Awaiting confirmation |
| QR sharing | Awaiting confirmation |
| Apple Wallet | Awaiting confirmation |
| Google Wallet | Awaiting confirmation |
| Relationship records with notes | Awaiting confirmation |
| Team admin and roles | Awaiting confirmation |
| Audit log | Awaiting confirmation |
| Analytics | Awaiting confirmation |
| Self-serve export | Awaiting confirmation |
| Cryptographic (clone-resistant) chips | Awaiting confirmation |
| Card status checker | Awaiting confirmation |