Security

Built for industries where security isn't optional.

High-risk merchants handle sensitive financial data. We protect it with enterprise-grade encryption, compliance certifications, and strict access controls.

SOC 2 Type II
PCI DSS Level 1
GDPR Compliant
99.9% Uptime SLA
🔒

Encryption at Rest and in Transit

All data is encrypted using AES-256 at rest. Every connection uses TLS 1.3. Processor credentials are encrypted with a dedicated ENCRYPTION_KEY before being stored.

  • AES-256 encryption at rest
  • TLS 1.3 for all connections
  • Encrypted processor API keys
  • No raw card numbers ever stored
🏛

SOC 2 Type II Compliant

HighRiskIntel operates under SOC 2 Type II controls covering Security, Availability, and Confidentiality. Annual third-party audits validate our controls.

  • Annual third-party audits
  • Security, Availability, Confidentiality
  • Continuous control monitoring
  • Audit reports available on request
🛡

PCI DSS Level 1

We are PCI DSS Level 1 compliant — the highest level of payment card industry security standards. We never store, process, or transmit cardholder data.

  • PCI DSS Level 1
  • No cardholder data stored
  • Quarterly network scans
  • Annual on-site assessment
🔑

Authentication & Access Control

Role-based access controls ensure users only see their own merchant data. Sessions are signed with HMAC-SHA256 and expire after 7 days of inactivity.

  • Supabase Auth (email/password)
  • HMAC-SHA256 signed sessions
  • Row-level security via Supabase
  • No cross-merchant data access
🌍

GDPR & Privacy

We are GDPR compliant. Merchants can request deletion of all their data at any time. We never sell or share merchant data with third parties.

  • GDPR compliant
  • Right to erasure (data deletion)
  • No third-party data sharing
  • EU data residency available on Enterprise

Infrastructure Security

Hosted on Vercel and Supabase with 99.9% uptime SLA. Automatic DDoS protection, WAF, and rate limiting on all public endpoints.

  • 99.9% uptime SLA
  • DDoS protection
  • Rate limiting on all endpoints
  • Supabase managed Postgres

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a security issue in HighRiskIntel, please report it to our security team. We'll acknowledge your report within 24 hours and work with you to resolve it promptly.

Report a vulnerability →