Security & Compliance

Enterprise‑grade controls, transparent posture, and continuous improvement.

Certifications

  • SOC 2 Type II
  • NACHA compliant ACH operations
  • ISO 27001 aligned controls
  • GDPR alignment for applicable data
  • OWASP ZAP DAST scans (Oct 2025) with all critical/high resolved

Transport & Data

  • TLS 1.2+ only with HSTS (includeSubDomains; preload)
  • Encryption in transit and at rest (AES‑256 at rest)
  • Signed webhooks with replay protection (HMAC)
  • Tokenized bank data; secrets never logged

Application Security

  • Security headers: CSP, HSTS, COEP/COOP/CORP, Referrer‑Policy, Permissions‑Policy
  • Role‑based access, audit trails, account lockout protection
  • Scrypt + Bcrypt password hashing
  • Automated dependency and bundle scanning in CI

Availability

  • Target 99.95% uptime
  • Global edge delivery and redundancy
  • Incident response and status updates