Hey hackers
We're launching our card issuing product and hit a pretty obvious obstacle.
How do we securely send the full card number + Expiration + CVV to our cardholder?
Of course, they can wait for the physical card to arrive but we do offer the instant option and I'm wondering what standard operating procedures issuers use for this.
Context, my background is in the payments space and I'm now wondering if PCI compliance applies to issuers or only merchants.