Security & Compliance
Enterprise‑grade controls, transparent posture, and continuous improvement.
Certifications
- SOC 2 Type II
- NACHA compliant ACH operations
- ISO 27001 aligned controls
- GDPR alignment for applicable data
- OWASP ZAP DAST scans (Oct 2025) with all critical/high resolved
Transport & Data
- TLS 1.2+ only with HSTS (includeSubDomains; preload)
- Encryption in transit and at rest (AES‑256 at rest)
- Signed webhooks with replay protection (HMAC)
- Tokenized bank data; secrets never logged
Application Security
- Security headers: CSP, HSTS, COEP/COOP/CORP, Referrer‑Policy, Permissions‑Policy
- Role‑based access, audit trails, account lockout protection
- Scrypt + Bcrypt password hashing
- Automated dependency and bundle scanning in CI
Availability
- Target 99.95% uptime
- Global edge delivery and redundancy
- Incident response and status updates