Security & Compliance

Security is the bedrock of our platform.

Mast is built for regulated banks and lenders. Our platform combines independent certifications, defence-in-depth engineering and 24/7 operations, so you can move fast without compromising on trust.

Certifications

Independently verified. Continuously audited.

ISO 27001

Certified information security management, audited by an independent third party.

CyberEssentials Plus

UK government-backed certification verifying protection against common cyber threats.

24/7 Monitoring

Continuous infrastructure, performance and security monitoring with on-call response.

GDPR & UK DPA

Data processing agreements, DPIAs, and privacy-by-design across the platform.

PCI-aware

No cardholder data stored; integrations designed to keep clients out of PCI scope.

How we protect your data

Six pillars of a defence-in-depth posture.

Data protection
  • AES-256 encryption at rest across databases, object storage and backups.
  • TLS 1.2+ enforced in transit; HSTS, modern ciphers, forward secrecy.
  • Field-level encryption for sensitive PII and financial data.
  • Customer-managed keys available on enterprise deployments.
Identity & access
  • IP allowlisting gates all production access today; every connection is source-verified.
  • Role-based access control with least-privilege defaults and regular access reviews.
  • Mandatory MFA for all Mast personnel and customer administrators.
  • Just-in-time production access with full session recording and audit trail.
  • SSO via SAML and OIDC - plus SCIM provisioning - is on the near-term roadmap for enterprise deployments.
Application security
  • Secure SDLC with code review, SAST, DAST and dependency scanning.
  • Annual third-party penetration tests and continuous vulnerability scanning.
  • Public responsible disclosure programme with defined SLAs.
  • Signed builds and immutable, reproducible deployment pipelines.
Infrastructure & resilience
  • Isolated tenant environments on hardened cloud infrastructure.
  • Segmented networks, WAF, DDoS protection and egress controls.
  • Automated backups, point-in-time recovery, and cross-region redundancy.
  • Documented RTO/RPO with regular disaster recovery exercises.
Governance & compliance
  • ISMS aligned to ISO 27001; policies reviewed at least annually.
  • Vendor risk management and continuous third-party monitoring.
  • Change management, audit logging and evidence retention.
  • Regulatory alignment with FCA operational resilience expectations.
Privacy
  • GDPR and UK Data Protection Act 2018 compliant by design.
  • Data residency options and configurable retention policies.
  • Data subject request tooling built into the platform.
  • Sub-processor register maintained and published on request.
Incident response

Ready before something goes wrong.

We run a documented incident response plan, tested regularly through tabletop exercises and live drills. When an event happens, we detect quickly, contain aggressively and communicate transparently.

< 15 min
Detection to on-call acknowledgement for Sev-1 events.
< 1 hr
Customer notification target for confirmed security incidents.
24 / 7 / 365
Security operations coverage and incident response readiness.
Responsible disclosure

Report a vulnerability

We welcome reports from the security research community. Email security@usemast.com with details and reproduction steps. We acknowledge within one business day and keep you informed through resolution.

Trust documentation

Request our security pack

Enterprise customers can request our full trust pack, including certifications, penetration test summaries, access-control attestations, DPA templates and sub-processor lists. Contact hello@usemast.com.