LegalTERMSPRIVACYCOOKIESCOMPLIANCEACCEPTABLE USESECURITYREFUNDSPAYMENT SERVICESFINANCIAL SERVICESV2 · EFFECTIVE 1 AUG 2026

Security & Responsible Disclosure

This page states commitments and procedure. It deliberately does not describe internal architecture; a security overview for enterprise due diligence is available under NDA via legal@bolrach.com.

1 · Our commitments

Customer data is encrypted in transit, and stored files are encrypted at rest. Bolrach Pay runs in test mode until our registrations are complete, so no live customer funds are held. Access to production systems is role-scoped, individually attributed and audited. Card data is handled by our payment processors' PCI DSS certified systems; full card numbers never touch merchant code or our dashboards. Moving money requires signing in again within the last fifteen minutes. We test our own defences continuously.

IN PLAIN LANGUAGEYour money and data are locked separately from ours, every touch is attributable to a person, and a stolen login alone can never move funds.
2 · Your part

Security is shared. You agree to: use the passkey and multi-factor options we provide; scope team roles to the minimum needed; keep payout details current and confirm our cooling-window checks; and tell us through a ticket immediately if you suspect account compromise, because speed changes outcomes. We will never ask for your credentials by phone, mail or chat; anyone who does is not us.

3 · Responsible disclosure — the programme

If you find a vulnerability in any Bolrach surface, report it through the security report form linked from every footer; reports are end-to-end encrypted and reach the security team directly. Give us reasonable detail to reproduce. In return: we confirm receipt within 2 business days, assign a named handler, keep you informed to a stated fix timeline, and credit you if you wish once the fix ships. Good-faith research within scope will not lead to legal action by Bolrach — that is our safe-harbour commitment, and it covers testing against your own accounts and data only.

IN PLAIN LANGUAGEFind something, tell us safely, and we treat you as a colleague: a real human answers, a clock applies, and good faith is protected in writing.
4 · Out of scope

Denial-of-service testing, spam, social engineering of staff or customers, physical intrusion, and testing against accounts or data that are not yours are outside the safe harbour. Automated scanner noise without a demonstrated impact is triaged last.

5 · Incidents

If an incident materially affects your data or funds we notify you without undue delay with what we know, what we are doing, and what you should do — and we file whatever regulatory notifications the law requires. The status page tells the truth during service incidents; we do not relabel outages as maintenance.