Security is the bedrock of our platform.
Mast is built for regulated banks and lenders. Our platform combines independent certifications, defence-in-depth engineering and 24/7 operations, so you can move fast without compromising on trust.
Independently verified. Continuously audited.
Certified information security management, audited by an independent third party.
UK government-backed certification verifying protection against common cyber threats.
Continuous infrastructure, performance and security monitoring with on-call response.
Data processing agreements, DPIAs, and privacy-by-design across the platform.
No cardholder data stored; integrations designed to keep clients out of PCI scope.
Six pillars of a defence-in-depth posture.
- AES-256 encryption at rest across databases, object storage and backups.
- TLS 1.2+ enforced in transit; HSTS, modern ciphers, forward secrecy.
- Field-level encryption for sensitive PII and financial data.
- Customer-managed keys available on enterprise deployments.
- IP allowlisting gates all production access today; every connection is source-verified.
- Role-based access control with least-privilege defaults and regular access reviews.
- Mandatory MFA for all Mast personnel and customer administrators.
- Just-in-time production access with full session recording and audit trail.
- SSO via SAML and OIDC - plus SCIM provisioning - is on the near-term roadmap for enterprise deployments.
- Secure SDLC with code review, SAST, DAST and dependency scanning.
- Annual third-party penetration tests and continuous vulnerability scanning.
- Coordinated vulnerability management with defined remediation SLAs.
- Signed builds and immutable, reproducible deployment pipelines.
- Isolated tenant environments on hardened cloud infrastructure.
- Segmented networks, WAF, DDoS protection and egress controls.
- Automated backups, point-in-time recovery, and cross-region redundancy.
- Documented RTO/RPO with regular disaster recovery exercises.
- ISMS aligned to ISO 27001; policies reviewed at least annually.
- Vendor risk management and continuous third-party monitoring.
- Change management, audit logging and evidence retention.
- Regulatory alignment with FCA operational resilience expectations.
- GDPR and UK Data Protection Act 2018 compliant by design.
- Data residency options and configurable retention policies.
- Data subject request tooling built into the platform.
- Sub-processor register maintained and published on request.
Ready before something goes wrong.
We run a documented incident response plan, tested regularly through tabletop exercises and live drills. When an event happens, we detect quickly, contain aggressively and communicate transparently.