Legal
Trust Center
What is true today: independent VAPT testing completed, no certifications currently held, and a dated roadmap for the ones we are working towards.
1. Certification status — stated plainly
WOWBANK does not currently hold SOC 2, ISO 27001 or PCI-DSS certification. We do not claim, imply or display badges for certifications we have not been awarded.
Completed independent testing on record: a vulnerability assessment and penetration test (VAPT) conducted by SISA. The scope covered the platform's externally reachable application surface and authenticated application testing. A summary of scope and remediation status is available to prospective clients under NDA on request; findings raised in that assessment have been triaged and remediated or risk-accepted with documented rationale.
2. Certification roadmap
Our current targets, stated as intent rather than achievement:
- PCI-DSS — scoping and gap assessment underway for card-processing components; target assessment window 2027.
- ISO 27001 — ISMS documentation and control mapping in progress; target certification 2027.
- SOC 2 Type I, then Type II — planned after the ISMS is operating; readiness assessment to follow ISO work.
- Annual re-test — VAPT repeated annually and after major architectural change.
3. Our approach
Security is designed into the platform rather than added at the edge: least-privilege access, segregation of duties in operational tooling, audit trails on configuration changes, and environment separation between sandbox, test and production.
Deployment-specific controls are agreed with each client and documented in the contract and runbooks for that deployment.
4. Subprocessors and third-party dependencies
Parts of a WOWBANK deployment rely on third-party services — identity verification and eKYC, AML and sanctions screening data, cloud infrastructure, HSM services, communications providers and, where relevant, card scheme connectivity.
The specific vendors used in a given deployment are disclosed in writing during due diligence, subject to each vendor's own disclosure terms. We do not publish vendor names on this page without the vendor's and the client's sign-off. A current subprocessor list can be requested for a named engagement.
5. Data ownership
Customer and operational data belong to the institution that owns the deployment. Access, export and migration terms are defined up front in the agreement.
6. Sandbox safety
The evaluation sandbox is for synthetic data only. Never submit real customer records, production credentials or live card data to it.
7. Responsible disclosure
If you believe you have found a vulnerability in this website or our sandbox, report it to us before disclosing it publicly. Include the affected URL or endpoint, reproduction steps and any supporting evidence.
Please do not run automated scans that degrade service, access data that is not yours, or attempt social engineering. We will acknowledge legitimate reports and keep you updated while we investigate.
8. Contact
Send reports, certification evidence requests and security questionnaires through the contact form marked “Security”. Last updated 17 August 2026.

