Skip to main content

DEMO PLATFORMThis is a demonstration platform. Not licensed for real financial transactions. Do not invest real money.

Legal Notice

Security & Compliance

Bank-grade security protecting your data, investor information, and financial transactions. Our platform is built with institutional-grade security practices and regulatory compliance at its core.

Security Overview

High-Availability Infrastructure

Enterprise-grade infrastructure built for redundancy with automatic failover

AES-256 Encryption

All data encrypted at rest and in transit using bank-grade encryption standards

SOC 2 Type II

SOC 2 Type II certification targeted for Q3 2026 with annual audits

Data Encryption

Data at Rest

  • AES-256 encryption for all stored data
  • Encrypted database backups with point-in-time recovery
  • Secure key management with keys held outside the codebase and a controlled rotation process
  • Field-level encryption for sensitive investor data (tax and bank details)

Data in Transit

  • TLS 1.3 for all API communications
  • Perfect forward secrecy preventing decryption of past sessions
  • App Transport Security enforcing TLS-only connections in mobile apps
  • Encrypted webhooks with signature verification

Access Controls & Authentication

Role-Based Access Control (RBAC)

Granular permissions system ensuring users only access data required for their role. Separate permission sets for partners, developers, investors, and administrators.

  • Least privilege access by default
  • Audit trail for all permission changes
  • Rate limiting on authentication and API endpoints
  • API credential rotation on request

Multi-Factor Authentication

MFA is required for administrative and compliance accounts, and available for investor and trustee accounts.

  • TOTP authenticator apps (Google, Authy)
  • Backup recovery codes
  • Rate-limited login with lockout on repeated failures
  • Short-lived, signed session tokens

Security Questions?

Our security team is available to answer questions about our security practices, compliance status, or to provide additional documentation for your procurement process.

For security vulnerability reports, please email security@bondbricks.com