Security
What actually protects your account.
Not a wall of badges. This page says how your password and your transfer PIN are stored, what you can switch off yourself and how quickly, what is written down about your sign-ins, and who to tell the moment something looks wrong. Where a fact depends on the company operating this site rather than on the software it runs, it is marked as such instead of guessed.
✓
Passwords hashed, never stored readably
✓
A transfer PIN nobody here can read back
✓
Freeze your card yourself, in about a second
How credentials are stored
Two secrets, and what becomes of them.
Both are put through a one-way function before they are written down, so what the database holds cannot be turned back into what you typed — by us, or by anyone who ever got hold of it.
Your password
Hashed before it is stored and never kept in a form anyone can read — including us. If you forget it we can only help you set a new one; nobody here can tell you the old one.
Your transfer PIN
You are asked for it every time you send money, and it is stored the same way. We cannot show you the old one, and neither can anybody else. Transfers are refused until you set one.
Getting back in
A password reset works by sending a link to the email address on your account, and that link stops working after an hour. Nobody reads your old password back to you, because nobody can.
No system is perfectly secure, so we also ask you to protect your own credentials — see the terms.
Read the terms→In your account
Four things you can do without asking us.
Every one of these takes effect when you press it. None of them needs a phone call, and none of them can be undone by anybody but you.
Freeze the card
Freeze it the second you cannot find it. It stops in about a second, nothing else about your account changes, and you can unfreeze it the moment it turns up in a coat pocket.
Freeze my card→Change your password
From your account settings, using the password you have now. You will need the new one to sign back in, on this device and on every other.
Account settings→Check what a payment was
Every movement carries a reference, what it was, where it went and the balance it left behind. It is the quickest way to settle whether a payment you do not recognise is yours.
Your transactions→See what may leave your accounts
Two per-transfer limits apply — one for wire and crypto, one for bank and local transfers — alongside a switch that refuses every transfer before your PIN is even checked. Limits are set by us; ask if you need one raised.
Security settings→What is written down
The record kept about your account.
It is not there to profile you. It is kept so that unauthorised access can be detected and investigated, and so that we can answer you when you ask what happened and when.
Last sign-in
The time you last signed in
Password changes
The time your password was last changed
Email address
Whether it has been verified, and the tokens used to verify it or to reset a password
Two-factor
Whether it is switched on, and its recovery codes
Preferences
Your notification and communication settings
What you did here
The records created by what you do — transactions, requests and support messages
SITE OWNER — REPLACE THIS
Two-factor sign-in is not switched on for customers here.
The account record has fields for two-factor authentication and its recovery codes, and this page deliberately does not promise them, because nothing on the customer side of this site turns them on today — the second factor a customer actually has is the transfer PIN. If your deployment enables a second sign-in factor, describe it here and add it to the account screen. Until it does, do not.
Your money
Held apart from ours.
Your money is held separately from the money that runs the business. It is not used to fund the company, and it does not sit in the same place as the money that pays its bills.
SITE OWNER — REPLACE THIS
Who regulates this business.
Name the authority that authorises and regulates it, and the number a customer can look it up under on that authority's public register. Everywhere else this site says only “the authority named in our terms”, because a theme cannot know which one it is.
SITE OWNER — REPLACE THIS
Which deposit protection scheme applies.
Name the scheme that covers deposits where you operate — FSCS, FDIC, a national deposit guarantee scheme, or none at all — the amount it covers per person, and which of your accounts are eligible. Until it is named as a fact this site holds, the home page's protection badge and the deposit rows on the personal, business, savings and services pages show a generic sample in its place.
Your part
Four things only you can do.
01
Use a password you use nowhere else.
It is hashed here and cannot be read back. But a password reused on a site that is breached is a password somebody already has, and no amount of care at this end changes that.
02
Keep your transfer PIN to yourself.
Nobody here can read it back — including us. So treat any message asking you to confirm it, from anyone, as a fake, however convincingly it is written.
03
Freeze first, ask second.
If a payment or a sign-in was not you, freeze the card before you write to us. Freezing takes about a second and you can undo it yourself; a conversation is neither of those things.
04
Read the receipt before you worry.
Most payments people do not recognise are simply named differently by the shop. The receipt says what it was, where it went and the balance it left behind.
If something is wrong
Tell us straight away.
A card gone, a payment you did not make, an email that does not look right — any of those, at any hour. Freeze the card yourself first if it is the card; it is faster than we are.
Chat
24/7
In the app, or the bubble on this page
Usually under a minute
Phone
24/7
+1 (800) 555-0199
Straight through, no menu
Mon–Fri
support@securetrust360.com
Within one working day
If you are not satisfied with how we handle it, the complaints procedure sets out what happens next and by when.
Read the complaints procedure→Site owner
What this page deliberately does not claim.
A theme cannot hold a certificate, commission an audit or run a disclosure programme. Everything below is left for the company operating this site to complete — or to leave out, honestly, rather than to imply.
SITE OWNER — REPLACE THIS
Certifications and audits.
If this business holds a security certification — ISO/IEC 27001, SOC 2, PCI DSS — name it here with its scope, the body that issued it and the date of the last audit, and link the certificate itself. Nothing in this software evidences one, so nothing on this page claims one. A seal you have not earned is the fastest way to lose an argument with a regulator.
SITE OWNER — REPLACE THIS
Independent testing.
If your systems are penetration-tested or reviewed by an outside party, say by whom and how often, and what happens to what they find. Say nothing at all rather than “regularly”.
SITE OWNER — REPLACE THIS
Reporting a vulnerability.
Give the address a security researcher should report a problem to, and the terms you offer them for doing it quietly. Without one, somebody who finds a fault in this site has nowhere to send it, and publishing is their remaining option.
