Legal
Security & Responsible Disclosure
How we think about platform security, data ownership and vulnerability reports.
1. Our approach
Security is designed into the platform rather than added at the edge: least-privilege access, segregation of duties in operational tooling, audit trails on configuration changes, and environment separation between sandbox, test and production.
Deployment-specific controls are agreed with each client and documented in the contract and runbooks for that deployment.
2. Data ownership
Customer and operational data belong to the institution that owns the deployment. Access, export and migration terms are defined up front in the agreement.
3. Sandbox safety
The evaluation sandbox is for synthetic data only. Never submit real customer records, production credentials or live card data to it.
4. Responsible disclosure
If you believe you have found a vulnerability in this website or our sandbox, report it to us before disclosing it publicly. Include the affected URL or endpoint, reproduction steps and any supporting evidence.
Please do not run automated scans that degrade service, access data that is not yours, or attempt social engineering. We will acknowledge legitimate reports and keep you updated while we investigate.
5. Contact
Send reports and security questions through the contact form marked “Security”. Last updated 17 August 2026.

