Security is the bedrock of our platform.
Mast is built for regulated banks and lenders. Our platform combines independent certifications, defence-in-depth engineering and 24/7 operations, so you can move fast without compromising on trust.
Independently verified. Continuously audited.
Certified information security management, audited by an independent third party.
UK government-backed certification verifying protection against common cyber threats.
Continuous infrastructure, performance and security monitoring with on-call response.
Data processing agreements, DPIAs, and privacy-by-design across the platform.
No cardholder data stored; integrations designed to keep clients out of PCI scope.
Six pillars of a defence-in-depth posture.
- AES-256 encryption at rest across databases, object storage and backups.
- TLS 1.2+ enforced in transit; HSTS, modern ciphers, forward secrecy.
- Field-level encryption for sensitive PII and financial data.
- Customer-managed keys available on enterprise deployments.
- IP allowlisting gates all production access today; every connection is source-verified.
- Role-based access control with least-privilege defaults and regular access reviews.
- Mandatory MFA for all Mast personnel and customer administrators.
- Just-in-time production access with full session recording and audit trail.
- SSO via SAML and OIDC - plus SCIM provisioning - is on the near-term roadmap for enterprise deployments.
- Secure SDLC with code review, SAST, DAST and dependency scanning.
- Annual third-party penetration tests and continuous vulnerability scanning.
- Public responsible disclosure programme with defined SLAs.
- Signed builds and immutable, reproducible deployment pipelines.
- Isolated tenant environments on hardened cloud infrastructure.
- Segmented networks, WAF, DDoS protection and egress controls.
- Automated backups, point-in-time recovery, and cross-region redundancy.
- Documented RTO/RPO with regular disaster recovery exercises.
- ISMS aligned to ISO 27001; policies reviewed at least annually.
- Vendor risk management and continuous third-party monitoring.
- Change management, audit logging and evidence retention.
- Regulatory alignment with FCA operational resilience expectations.
- GDPR and UK Data Protection Act 2018 compliant by design.
- Data residency options and configurable retention policies.
- Data subject request tooling built into the platform.
- Sub-processor register maintained and published on request.
Ready before something goes wrong.
We run a documented incident response plan, tested regularly through tabletop exercises and live drills. When an event happens, we detect quickly, contain aggressively and communicate transparently.
Report a vulnerability
We welcome reports from the security research community. Email security@usemast.com with details and reproduction steps. We acknowledge within one business day and keep you informed through resolution.
Request our security pack
Enterprise customers can request our full trust pack, including certifications, penetration test summaries, access-control attestations, DPA templates and sub-processor lists. Contact hello@usemast.com.