Security

Security

Last updated: 26 January 2026

1. Our approach to security

We take the security of our systems and the protection of data seriously. This page provides an overview of the technical and organisational measures we use to help protect information processed in connection with our website and services.

This overview is intentionally high level and may be updated as our program evolves. Detailed security documentation may be available to partners under NDA.

2. Governance and policies

  • Security responsibilities assigned to named owners and reviewed periodically.
  • Risk assessment and control selection based on the nature of the data and services provided.
  • Policies covering access control, acceptable use, incident management, vendor management, and secure development practices.

3. Access controls

  • Least-privilege access: access is granted based on role and business need.
  • Multi-factor authentication (MFA) for administrative access where available.
  • Access reviews and timely removal of access on role change or departure.

4. Data protection measures

  • Encryption in transit for data transmitted over public networks (e.g., HTTPS/TLS).
  • Encryption at rest where supported by our infrastructure and service providers.
  • Segregation of environments (e.g., production and non-production) and controlled access to production systems.

5. Secure development and change management

  • Code review and testing prior to deployment.
  • Use of dependency management and monitoring for known vulnerabilities.
  • Change controls and logging for releases and configuration changes.

6. Monitoring, logging, and incident response

  • System monitoring and logging designed to detect security-relevant events.
  • Incident response procedures for triage, containment, eradication, recovery, and post-incident review.
  • Where appropriate, we will notify affected parties and regulators in line with applicable law and contractual commitments.

7. Third-party risk and Merchant of Record arrangements

We rely on reputable third-party service providers to operate parts of our services (for example: cloud infrastructure, communications tools, and payment services). Where a Merchant of Record payment provider processes payments, it is responsible for the security of payment card data and payment processing within its environment.

We assess suppliers based on risk and, where appropriate, seek security assurances and contractual protections.

8. Business continuity

  • Backups and recovery processes designed to support availability and resilience.
  • Procedures for handling outages and restoring services.

9. Responsible disclosure

If you believe you have found a security vulnerability, please report it to us responsibly. Do not publicly disclose vulnerabilities without giving us a reasonable opportunity to investigate and remediate.

Security contact:

  • Email: security@finbpm.tech
  • Postal address: Unit G02, EuroCity, Europort Avenue, Gibraltar GX11 1AA

10. Changes to this page

We may update this page from time to time. When we do, we will update the “Last updated” date at the top.