Ticketing, entry, concessions, retail, and partner activation resolved to one fan.
Read the case study →Built from network transaction data and interviews with finance leads across sports and live entertainment.
Get the report →NHL, AHL, CFL and WNBA clubs, MLS, a Las Vegas resort, and the platforms underneath them.
See the roster →The questions an enterprise buyer asks before the demo, answered before the demo. Take them into every payments conversation you have this year, including the one with us.

The card credential is tokenised at the point of authorisation. Primary account numbers do not enter club systems, which is what takes those systems out of PCI scope rather than merely encrypting what is already there.
Ordr’s payment data runs on Cy4Secure, Cy4data’s persistent encryption platform. Most stacks encrypt data at rest and in transit, then decrypt it to work on it. That decryption window is the gap Cy4Secure closes: the data stays encrypted while it is queried, processed and shared, so a stolen credential or a copied database yields cipher text rather than a record.
AES-256 applied at the element level, down to a single field or record. Databases operate natively on the encrypted data, so nothing is decrypted to run a query and there is no performance cost to carrying it.
Encryption keys are held separately from the data, with no connection between key locations, data stores and users. Possession of a password is not possession of the keys, which is what takes an insider or a supply chain compromise off the table.
Keys are issued only to authorised users and applications. Access is monitored in real time, abnormal patterns are stopped by machine learning detection and multi factor verification is forced, so credential dumping, account takeover and man in the middle attempts fail at the key rather than at the door.
Persistent encryption is how Ordr meets PCI DSS requirements 3 and 4, protecting stored cardholder data and encrypting it in transmission, and it supports the same obligations under GDPR and CCPA. Platform details from the Cy4data security and compliance certification issued for Ordr, reviewed annually. The requirement by requirement mapping is in the technical pack.
Ordr holds PCI DSS, SOC 1 and SOC 2, and is P2PE capable. The technical pack names the version, the assessment type, the observation window and the criteria in scope, because a certification without those four things is a word rather than a claim.
Version 3.2.1 was retired on 31 March 2024, and the 51 future dated requirements in v4.0 became mandatory on 31 March 2025. Any assessment conducted in 2026 is conducted against v4.0.1.
SOC 1 addresses controls relevant to financial reporting. SOC 2 addresses the trust services criteria. Security is mandatory in every SOC 2. The others are selected against the commitments the provider has actually made.
We say capable because that is the accurate word for the hardware and the architecture. Vendors who blur those two claims are worth a follow up question.
PCI DSS version status from the PCI Security Standards Council.
On 1 April 2026 the Visa merchant excessive threshold under the Acquirer Monitoring Program dropped from 220 basis points to 150. An operator that was comfortably compliant under the old ceiling can be in breach today without changing a single operational practice.
The merchant excessive threshold from 1 April 2026, down from 220. Acquirer level thresholds sit tighter still, at 50 basis points standard and 70 excessive.
Visa, 2026Open the fact sheet →The ratio is measured by transaction count rather than value, so a high volume game night carries proportionally more exposure than the same revenue spread across fewer, larger transactions.
Why arenas are exposedSee Transact IQ →Internal cost plus third party fees on a single chargeback, before the value of the goods. The Vegas Golden Knights recovered $82,500 of it.
Mastercard, June 2026Open the source →There is a trap in the obvious response. Tightening fraud rules to decline more transactions shrinks the denominator without shrinking the numerator, which can push the ratio further out of compliance. Approving more legitimate transactions while reducing genuine disputes requires transaction level evidence, not a stricter rule.
A bank note is engraved rather than printed because the pattern is the proof. The same idea runs through this platform: one continuous surface where every transaction, every fan and every partner activation sits in the same weave rather than in nine separate documents.
Send the question your security team would ask if they were on the call. If the answer is not flattering to us we will still give it to you in writing.
Switching to Ordr was one of the smartest and easiest decisions we've made. By moving our payments under Ordr, we gained visibility into hidden costs and started unlocking valuable, revenue-driving data.