Every transaction is encrypted, every control is independently audited, and every report from a researcher gets an answer.

How we protect the platform

The controls below are a summary. The complete list, with live status for each one, lives on our trust center.

Encryption everywhere

Data is encrypted at rest and in transit. Keys follow a documented key management policy and production databases use unique credentials.

Least-privilege access

Access is granted per role, reviewed regularly and revoked on offboarding. MFA is required for every critical service and production deploy access is restricted.

Hardened infrastructure

Infrastructure is deployed as code, changes require review and are logged, storage is never public and a web application firewall fronts the platform.

Monitoring and incident response

Audit logs are collected across systems, infrastructure is monitored around the clock and incidents follow a documented, exercised response plan.

Backups and resilience

Automated backups, isolated recovery data and business continuity plans that are tested, not just written, keep the platform available.

Vendor and risk management

Every vendor is inventoried and risk assessed, critical vendors have exit strategies and risk assessments drive treatment plans.

Built into every stage of how we work

Internal security

  • Company-managed devices with disk encryption, firewall and anti-malware enforced.
  • Password manager and MFA required for every employee and contractor.
  • Reference checks on hire, confidentiality agreements signed by everyone.
  • Security awareness training on onboarding and on a recurring schedule.
  • Access is reviewed regularly and revoked the day someone leaves.

Secure development

  • Every change to code and infrastructure goes through review before it ships.
  • Automated dependency and vulnerability scanning on the codebase and the infrastructure.
  • Patches are applied automatically and findings are tracked to remediation.
  • A documented software development lifecycle with secure engineering principles.
  • Independent penetration testing at least every 12 months.

Doing due diligence on BlindPay?

SOC 2 report, pentest summary and policies are available on request. Email compliance@blindpay.com and we will send them over.