Our Commitment to Trust
The foundation of the financial technology industry is trust. Our security framework is built on three pillars:
- Information Security Program: Protecting the Confidentiality, Integrity, and Availability (CIA) of data.
- Data Lifecycle Governance: Principled management from collection to disposal.
- Proactive Assurance: Continuous independent testing and validation.
I. Information Security Program
Governance
Security is a shared responsibility. Our Information Security Officer (ISO) oversees the program, while our Executive Management ensures resources are allocated to maintain a robust defense posture.
Access Control (Zero Trust)
We operate on a Zero Trust philosophy. No user or system is trusted by default. We enforce the Principle of Least Privilege, ensuring users only have access to the data strictly necessary for their role. Multi-Factor Authentication (MFA) is mandatory for all internal systems.
Encryption Standards
- Data in Transit: Protected via TLS 1.2+.
- Data at Rest: Protected via AES-256 military-grade encryption.
II. Proactive Security Assurance
We don't just set defenses and hope for the best. We actively test them.
Penetration Testing
We engage qualified, independent third-party security firms to conduct regular penetration tests (simulated cyberattacks) against our Web/Mobile Apps, APIs, and Cloud Infrastructure.
Vulnerability Management
All code undergoes automated Static (SAST) and Dynamic (DAST) application security testing before deployment.