Trust & security
Designed for regulated cross-border flows. Non-custodial by architecture, audit-ready by default.
Certifications & standards
SOC 2 Type II
In progress. Targeted attestation completion in Q4.
ISO 27001
Roadmap. Aligned to controls; certification scheduled post-pilot.
GDPR
EU data residency by default. Data Processing Agreement available on request.
PCI-DSS scope
Out of scope by design. Bridge does not store card data; payment instruments remain with regulated partners.
Security architecture
Non-custodial
Bridge does not custody funds. Regulated partners execute regulated legs and hold funds throughout settlement.
Pre-execution policy gating
Compliance, sanctions, KYB/KYC, and corridor rules evaluated before funds move.
Encrypted in transit and at rest
TLS 1.3 for all API traffic. AES-256 at rest. Secrets managed via cloud KMS with rotation.
Audit-ready logging
Event-based logging with timestamps, leg-by-leg status, and exportable payloads for reconciliation.
Role separation
Maker/checker workflows for sensitive operations. API keys scoped per integration.
Incident response
24h initial response SLA for security reports. Public status page for operational events.
Sub-processors
Vendors that process customer or transaction data on our behalf. Updated as our infrastructure evolves.
Report a vulnerability
Email security@ultrasoft.app. We acknowledge within 24 hours and coordinate disclosure for anything material.
Start a pilot. Validate real-time settlement.
Deploy in a controlled corridor and evaluate routing, cost, and execution performance.
