Security & Trust

Treasury-grade data protection.

We are building the financial brain of your business — so we treat your data with the same discipline a regulated bank would.

EU data residency

All customer data is stored and processed in the European Union. GDPR by default; no data leaves the EU.

Encryption everywhere

TLS 1.3 in transit and AES-256 at rest. Per-tenant encryption keys for sensitive ledger and bank data.

Read-only banking

We connect to banks through regulated PSD2 / open-banking aggregators. No payment initiation, no write access by default.

Modern infrastructure

Built on hardened cloud infrastructure with isolated environments, automated patching, and continuous vulnerability scanning.

Audit-ready logs

Every read and write to your financial context is logged with actor, source, and timestamp — exportable for your auditor.

Compliance roadmap

We are preparing for SOC 2 Type II and ISO 27001. We share our control matrix with prospects under NDA.

Responsible disclosure

Found a vulnerability? We appreciate coordinated disclosure. Email security@cashopti.com and we will respond within 2 business days.