LegalTERMSPRIVACYCOOKIESCOMPLIANCEACCEPTABLE USESECURITYREFUNDSPAYMENT SERVICESFINANCIAL SERVICESV2 · EFFECTIVE 1 AUG 2026

Security & Responsible Disclosure

This page states commitments and procedure. It deliberately does not describe internal architecture; a security overview for enterprise due diligence is available under NDA via [email protected].

1 · Our commitments

Customer data is encrypted in transit and at rest. Customer funds are segregated from company funds. Access to production systems is role-scoped, individually attributed and audited; no shared accounts exist. Payment card data is handled within PCI DSS scope by certified systems; full card numbers never touch merchant code or our dashboards. Moving money always requires a fresh, phishing-resistant confirmation beyond a login. We test our own defences continuously and engage independent assessors on a recurring cycle.

IN PLAIN LANGUAGEYour money and data are locked separately from ours, every touch is attributable to a person, and a stolen login alone can never move funds.
2 · Your part

Security is shared. You agree to: use the passkey and multi-factor options we provide; scope team roles to the minimum needed; keep payout details current and confirm our cooling-window checks; and tell us through a ticket immediately if you suspect account compromise, because speed changes outcomes. We will never ask for your credentials by phone, mail or chat; anyone who does is not us.

3 · Responsible disclosure — the programme

If you find a vulnerability in any Bolrach surface, report it through the security report form linked from every footer; reports are end-to-end encrypted and reach the security team directly. Give us reasonable detail to reproduce. In return: we confirm receipt within 2 business days, assign a named handler, keep you informed to a stated fix timeline, and credit you if you wish once the fix ships. Good-faith research within scope will not lead to legal action by Bolrach — that is our safe-harbour commitment, and it covers testing against your own accounts and data only.

IN PLAIN LANGUAGEFind something, tell us safely, and we treat you as a colleague: a real human answers, a clock applies, and good faith is protected in writing.
4 · Out of scope

Denial-of-service testing, spam, social engineering of staff or customers, physical intrusion, and testing against accounts or data that are not yours are outside the safe harbour. Automated scanner noise without a demonstrated impact is triaged last.

5 · Incidents

If an incident materially affects your data or funds we notify you without undue delay with what we know, what we are doing, and what you should do — and we file whatever regulatory notifications the law requires. The status page tells the truth during service incidents; we do not relabel outages as maintenance.