Security & Compliance

Security is the bedrock of our platform.

Mast is built for regulated banks and lenders. Our platform combines independent certifications, defence-in-depth engineering and 24/7 operations, so you can move fast without compromising on trust.

Certifications

Independently verified. Continuously audited.

ISO 27001

Certified information security management, audited by an independent third party.

CyberEssentials Plus

UK government-backed certification verifying protection against common cyber threats.

24/7 Monitoring

Continuous infrastructure, performance and security monitoring with on-call response.

GDPR & UK DPA

Data processing agreements, DPIAs, and privacy-by-design across the platform.

PCI-aware

No cardholder data stored; integrations designed to keep clients out of PCI scope.

How we protect your data

Six pillars of a defence-in-depth posture.

Data protection
  • AES-256 encryption at rest across databases, object storage and backups.
  • TLS 1.2+ enforced in transit; HSTS, modern ciphers, forward secrecy.
  • Field-level encryption for sensitive PII and financial data.
  • Customer-managed keys available on enterprise deployments.
Identity & access
  • IP allowlisting gates all production access today; every connection is source-verified.
  • Role-based access control with least-privilege defaults and regular access reviews.
  • Mandatory MFA for all Mast personnel and customer administrators.
  • Just-in-time production access with full session recording and audit trail.
  • SSO via SAML and OIDC - plus SCIM provisioning - is on the near-term roadmap for enterprise deployments.
Application security
  • Secure SDLC with code review, SAST, DAST and dependency scanning.
  • Annual third-party penetration tests and continuous vulnerability scanning.
  • Coordinated vulnerability management with defined remediation SLAs.
  • Signed builds and immutable, reproducible deployment pipelines.
Infrastructure & resilience
  • Isolated tenant environments on hardened cloud infrastructure.
  • Segmented networks, WAF, DDoS protection and egress controls.
  • Automated backups, point-in-time recovery, and cross-region redundancy.
  • Documented RTO/RPO with regular disaster recovery exercises.
Governance & compliance
  • ISMS aligned to ISO 27001; policies reviewed at least annually.
  • Vendor risk management and continuous third-party monitoring.
  • Change management, audit logging and evidence retention.
  • Regulatory alignment with FCA operational resilience expectations.
Privacy
  • GDPR and UK Data Protection Act 2018 compliant by design.
  • Data residency options and configurable retention policies.
  • Data subject request tooling built into the platform.
  • Sub-processor register maintained and published on request.
Incident response

Ready before something goes wrong.

We run a documented incident response plan, tested regularly through tabletop exercises and live drills. When an event happens, we detect quickly, contain aggressively and communicate transparently.

< 15 min
Detection to on-call acknowledgement for Sev-1 events.
< 1 hr
Customer notification target for confirmed security incidents.
24 / 7 / 365
Security operations coverage and incident response readiness.