No sections match this search.
Security model#
Controls are layered across identity, application, network and data. No single control is relied upon, and every privileged action is logged and reviewed.
Security is assessed against ISO 27001 and SOC 2 criteria, with independent testing at least twice a year.
Authentication#
- Passkeys and hardware security keys, supported on every account.
- One-time codes for step-up verification on sensitive actions.
- Device binding, with new devices confirmed before first use.
- Session expiry and immediate revocation from your security settings.
BINK will never ask for your password, one-time code or passkey over the phone, by email or in chat.
Data protection#
Traffic is encrypted with TLS 1.3. Stored data is encrypted with AES-256 and keys are managed in hardware security modules with split control. Card data is tokenised and handled within PCI DSS Level 1 scope.
Infrastructure#
Production runs in isolated environments with least-privilege access, mandatory review on every change, and immutable deployments. Access to production data requires approval and is time-bound.
| Control | Standard |
|---|---|
| Change management | Peer review and automated checks |
| Access | Least privilege, time-bound, logged |
| Backups | Encrypted, tested quarterly |
| Recovery | RPO 15 minutes · RTO 4 hours |
Monitoring#
Sessions, devices and payments are scored continuously. Unusual patterns trigger step-up verification, a temporary hold, or review by our fraud team.
Incident response#
- Detection and triage, on call at all times.
- Containment, with affected sessions or accounts isolated.
- Notification to affected customers and regulators within required timeframes.
- Post-incident review, published in summary where material.
Responsible disclosure#
We welcome coordinated disclosure. Report a vulnerability through the security channel in the application; we acknowledge within one business day and will not pursue action against good-faith research.
Testing must not access other customers' data, degrade service, or use social engineering against staff or customers.
Your role#
- Register a passkey and keep a backup method.
- Keep your device and browser up to date.
- Review devices and sessions in your security settings.
- Report anything unexpected without delay.
If you suspect unauthorised access, freeze your cards from the application and contact support immediately.
