Security & Compliance

Audited by people who do not take our word for it

Card data never touches your servers and never leaves ours unencrypted. Every control below is tested annually by an external assessor.

certified

PCI DSS

Level 1

Full scope, reassessed every 12 months.

certified

SOC 2

Type II

Report available under NDA in one day.

certified

ISO

27001

Information security management system.

aligned

GDPR

& LGPD

DPA signed at onboarding, no exceptions.

01 — Controls

How the money is protected

Four layers, each one independently auditable.

01 — Controls

How the money is protected

Four layers, each one independently auditable.

Data

Encrypted end to end

AES-256 at rest, TLS 1.3 in transit. Pan data is tokenized at the edge, so your systems store a reference and never a card number.

Data

Encrypted end to end

AES-256 at rest, TLS 1.3 in transit. Pan data is tokenized at the edge, so your systems store a reference and never a card number.

Keys

Hardware backed, rotated

Keys live in FIPS 140-2 Level 3 modules and rotate every 90 days. No engineer can export a key, only request an operation.

Keys

Hardware backed, rotated

Keys live in FIPS 140-2 Level 3 modules and rotate every 90 days. No engineer can export a key, only request an operation.

Access

Least privilege, logged

Production access is time-boxed, approved by a second person, and written to an append-only log you can query in your own dashboard.

Access

Least privilege, logged

Production access is time-boxed, approved by a second person, and written to an append-only log you can query in your own dashboard.

Funds

Segregated, never lent

Client balances sit in ring-fenced accounts at partner banks, reconciled daily against the ledger and reported monthly.

Funds

Segregated, never lent

Client balances sit in ring-fenced accounts at partner banks, reconciled daily against the ledger and reported monthly.

02 — Residency

Your data stays where you put it

Pick a region at onboarding and transaction data never replicates outside it. Backups, logs, and analytics follow the same boundary.

sa-east-1

São Paulo

LGPD, Bacen reporting

eu-west-1

Dublin

GDPR, PSD2 SCA

us-east-1

Virginia

SOC 2, state privacy laws

ap-southeast-2

Sydney

APRA CPS 234 aligned

Dark abstract texture lit with red light

03 — Transparency

Incidents are published, not buried

72h

Postmortem window

Every incident above severity 3 gets a public writeup with timeline, root cause, and the fix shipped.

72h

Postmortem window

Every incident above severity 3 gets a public writeup with timeline, root cause, and the fix shipped.

99.99%

Uptime, 90 days

Measured at the API edge, not at our load balancer. History goes back to the first production call.

99.99%

Uptime, 90 days

Measured at the API edge, not at our load balancer. History goes back to the first production call.

$50k

Bug bounty ceiling

Open program, no disclosure gag. Critical findings are triaged within four hours.

$50k

Bug bounty ceiling

Open program, no disclosure gag. Critical findings are triaged within four hours.

04 — Due diligence

Request the full security pack

SOC 2 report, PCI attestation, pen test summary, and a filled vendor questionnaire. Sent within one business day of the NDA.

04 — Due diligence

Request the full security pack

SOC 2 report, PCI attestation, pen test summary, and a filled vendor questionnaire. Sent within one business day of the NDA.

Create a free website with Framer, the website builder loved by startups, designers and agencies.