Trust & security

Designed for regulated cross-border flows. Non-custodial by architecture, audit-ready by default.

Posture summary

  • GDPR-aligned data handling
  • Policy-gated execution
  • Audit-ready transaction trail
  • Non-custodial architecture
  • SOC 2 controls in progress

Certifications & standards

SOC 2 Type II

In progress. Targeted attestation completion in Q4.

ISO 27001

Roadmap. Aligned to controls; certification scheduled post-pilot.

GDPR

EU data residency by default. Data Processing Agreement available on request.

PCI-DSS scope

Out of scope by design. Bridge does not store card data; payment instruments remain with regulated partners.

Security architecture

Non-custodial

Bridge does not custody funds. Regulated partners execute regulated legs and hold funds throughout settlement.

Pre-execution policy gating

Compliance, sanctions, KYB/KYC, and corridor rules evaluated before funds move.

Encrypted in transit and at rest

TLS 1.3 for all API traffic. AES-256 at rest. Secrets managed via cloud KMS with rotation.

Audit-ready logging

Event-based logging with timestamps, leg-by-leg status, and exportable payloads for reconciliation.

Role separation

Maker/checker workflows for sensitive operations. API keys scoped per integration.

Incident response

24h initial response SLA for security reports. Public status page for operational events.

Sub-processors

Vendors that process customer or transaction data on our behalf. Updated as our infrastructure evolves.

VendorPurposeRegion
Cloud infrastructureCompute, database, object storageEU
Email deliveryTransactional and operational notificationsEU
VerificationBot mitigation on public formsEU
Status pagePublic operational statusEU

Report a vulnerability

Email security@ultrasoft.app. We acknowledge within 24 hours and coordinate disclosure for anything material.

Start a pilot. Validate real-time settlement.

Deploy in a controlled corridor and evaluate routing, cost, and execution performance.