Security controls in this release
This page lists implemented controls. It does not claim SOC reports, PCI attestations, or bank-grade certifications.
- Passwords hashed with bcrypt; never stored in plaintext
- HTTP-only session cookies with expiration
- Login rate limiting by email and IP
- Server-side role checks for customer and administrator areas
- Customer records scoped by authenticated user id
- No public registration endpoint
- No collection of bank account numbers in website forms
- Security headers configured at the application edge
Report suspected issues to the configured support address. Do not include live credentials in the report.