Westfield is built to the standards finance and IT teams expect from anything that touches company funds: independently audited, encrypted end to end, and fully logged.
All data is encrypted with TLS 1.2+ in transit and AES-256 at rest, including card numbers, transaction records, and receipts.
Every user — from an employee cardholder to a finance admin — only sees the budgets, cards, and transactions their role permits.
Every policy check, approval, block, and limit change is recorded with a timestamp, actor, and the rule that applied — exportable for any audit.
Connect your identity provider so access is granted and revoked automatically as employees join or leave.
Card transactions are screened against fraud signals the same way they're screened against budget policy — before authorization.
Enterprise customers can choose where transaction and company data is stored to meet regional requirements.
Third-party security firms test the platform at least twice a year; summary reports are available under NDA.
A documented incident response process with defined customer notification timelines, reviewed as part of our SOC 2 audit.
We can share our SOC 2 report, pen test summaries, and a completed questionnaire under NDA.
Contact security team