This page states commitments and procedure. It deliberately does not describe internal architecture; a security overview for enterprise due diligence is available under NDA via legal@bolrach.com.
1 · Our commitmentsCustomer data is encrypted in transit, and stored files are encrypted at rest. Bolrach Pay runs in test mode until our registrations are complete, so no live customer funds are held. Access to production systems is role-scoped, individually attributed and audited. Card data is handled by our payment processors' PCI DSS certified systems; full card numbers never touch merchant code or our dashboards. Moving money requires signing in again within the last fifteen minutes. We test our own defences continuously.
Security is shared. You agree to: use the passkey and multi-factor options we provide; scope team roles to the minimum needed; keep payout details current and confirm our cooling-window checks; and tell us through a ticket immediately if you suspect account compromise, because speed changes outcomes. We will never ask for your credentials by phone, mail or chat; anyone who does is not us.
3 · Responsible disclosure — the programmeIf you find a vulnerability in any Bolrach surface, report it through the security report form linked from every footer; reports are end-to-end encrypted and reach the security team directly. Give us reasonable detail to reproduce. In return: we confirm receipt within 2 business days, assign a named handler, keep you informed to a stated fix timeline, and credit you if you wish once the fix ships. Good-faith research within scope will not lead to legal action by Bolrach — that is our safe-harbour commitment, and it covers testing against your own accounts and data only.
Denial-of-service testing, spam, social engineering of staff or customers, physical intrusion, and testing against accounts or data that are not yours are outside the safe harbour. Automated scanner noise without a demonstrated impact is triaged last.
5 · IncidentsIf an incident materially affects your data or funds we notify you without undue delay with what we know, what we are doing, and what you should do — and we file whatever regulatory notifications the law requires. The status page tells the truth during service incidents; we do not relabel outages as maintenance.