TRUST & SECURITY
INDEPENDENTLY CERTIFIED
Two standards. Two separate audits.
Covering how we handle cardholder data and how we manage information security across the business.
PCI
PCI DSS Certified
Our systems that store, process, and transmit cardholder data meet the Payment Card Industry Data Security Standard — covering network segmentation, encryption in transit and at rest, access control, and continuous monitoring.
ISO
ISO 27001 Certified
Our Information Security Management System (ISMS) is certified to ISO/IEC 27001, the international standard for managing information security risk — from employee access policies to incident response.
ISO/IEC 27001:2022
Download policy
What certification actually covers
Two standards, working together to protect both the payment and the platform around it.
Encryption everywhere
All data in transit is protected with TLS 1.2 and TLS 1.3, and sensitive data at rest is encrypted using industry-standard algorithms.
Continuous monitoring
Infrastructure and transaction activity are monitored around the clock, with automated alerting on anomalous behaviour.
Regular testing
Independent penetration testing and vulnerability scans are carried out on a recurring basis, with findings tracked to resolution.
Vetted people, vetted vendors
Employees complete security and data-handling training, and third-party vendors are assessed before they touch customer data.
Incident response
A documented response plan governs how we detect, contain, and disclose any security incident, tested through regular drills.
Security documentation
Our Vulnerability Assessment and Penetration Testing (VAPT) report is available on request (with an NDA).
Request VAPT Report →
Security contact
If you believe you’ve found a vulnerability in our systems, or you’re reporting a security incident, contact us directly.
