Security

Security and Vulnerability Disclosure

The controls we run, what we claim and do not claim, and how to report a weakness without fear of a lawsuit.
Document Information
Effective: September 8, 2026
Last updated: September 8, 2026
Next review: September 8, 2027
Applies to: All Banrox systems and the data in them
Reporting
Report a vulnerability there. We acknowledge within 2 business days and will not pursue legal action for good faith research inside the rules below.
No unverified badges
We publish only certifications we actually hold. Where we hold none for a given framework, this page says so plainly.

1. What We Claim, and What We Do Not

Certifications we hold: none, at the effective date of this page. Banrox does not currently hold a SOC 2 Type I or Type II report, an ISO 27001 certificate, a PCI DSS Attestation of Compliance in its own name, or any other third party security certification. We say so here because a security badge a company has not earned is itself a security problem, and because a partner or a regulator checking us is entitled to a straight answer. When we complete an audit we will publish the report type, the auditor, the period covered, and how to request the report under a confidentiality agreement.

Card payments are handled by a PCI DSS validated payment processor. Banrox does not store, process, or transmit full primary account numbers on its own systems, and card data is tokenised by the processor.

Banrox is not a bank and holds no deposits. No Banrox product is insured by the Federal Deposit Insurance Corporation or by the National Credit Union Administration, and no page on this site should say or imply otherwise. If you find one that does, report it to [email protected] and we will correct it.

2. The Security Programme We Actually Run

Banrox maintains a written information security programme appropriate to its size, complexity, and the sensitivity of the information it holds, as required by the Gramm-Leach-Bliley Act Safeguards Rule at 16 C.F.R. Part 314. Its elements:

ElementWhat it means here
Named accountabilityOne qualified individual is responsible for the programme and reports periodically to the board on its status, risks and incidents.
Written risk assessmentDocumented, reviewed at least annually and after any material change, covering confidentiality, integrity and availability.
Access controlLeast privilege, role based, reviewed periodically, revoked on the day a person leaves.
Multi factor authenticationRequired for administrative access to systems holding personal information, and offered to members for their own accounts.
EncryptionPersonal information encrypted in transit over public networks and at rest.
Data inventoryA record of what personal information we hold, where it lives, who can reach it, and when it is destroyed.
Secure developmentCode review, dependency and secret scanning, separate environments, and no production data in test systems.
Monitoring and testingContinuous logging and monitoring, vulnerability assessment, and penetration testing on the cadence the Safeguards Rule requires.
Vendor oversightSecurity review before onboarding, contractual security obligations, and periodic reassessment. See Service Providers and Data Recipients.
TrainingSecurity awareness training for staff, with role specific training for engineering and support.
Incident responseA written plan covering detection, containment, eradication, recovery, notification and post incident review, which is exercised rather than filed.
Change managementDocumented approval and rollback for production changes.

We also run edge protection against bot traffic, credential stuffing, denial of service and scraping, device and network risk signals at signup and login to stop account takeover, and rate limiting on every authentication and form endpoint.

3. If Something Goes Wrong

If personal information about you is subject to a breach, we will investigate, contain it, and notify you and the applicable regulators within the deadlines the law sets. Where unencrypted personal information about 500 or more consumers is acquired without authorisation, we will notify the Federal Trade Commission within 30 days as the Safeguards Rule requires, and we will meet every applicable state notification deadline.

Our notice will say what happened, when, what categories of information were involved, what we have done, what we are doing next, and what you can do, including how to place a free credit freeze. We will not delay a notice to manage publicity, and we will not describe a breach as an incident to make it sound smaller.

4. What You Control

  • Use a password that is unique to Banrox. Reused passwords are how most account takeovers start.
  • Turn on multi factor authentication in your account settings.
  • Never share a one time code. Banrox will never ask you for one, on any channel, for any reason.
  • Check the sender address on any email claiming to be Banrox. We send only from banrox.com.
  • Tell us at [email protected] if you see activity you do not recognise. We would rather chase a false alarm than miss a real one.

5. Vulnerability Disclosure Programme

Safe harbour. If you research in good faith and follow the rules below, Banrox will consider your activity authorised, will not initiate or support civil or criminal action against you, will not report you to law enforcement, and will make it known to any third party who takes action that your research was authorised. If legal action is brought by someone else because of your good faith research, we will say so on the record.

Rules of engagement

  • Test only against your own account or an account you have written permission to use
  • Stop as soon as you can demonstrate the issue, and do not view, copy, retain or transmit any data belonging to another person
  • No denial of service or resource exhaustion testing, no social engineering of staff, members or vendors, no physical intrusion, no spam or phishing
  • Do not modify or destroy data, and do not degrade service for anyone else
  • Report privately and give us a reasonable time to fix before any publication, and agree the date with us
  • Comply with all applicable law, and do not condition disclosure on payment

In scope

banrox.com and its subdomains, the Banrox member dashboard, and Banrox APIs. Out of scope: third party services we do not operate, findings that require a compromised device or a person to be tricked, reports generated purely by an automated scanner with no demonstrated impact, missing headers or informational TLS findings with no exploit path, and rate limiting on unauthenticated public pages.

How to report and what happens next

  • Email [email protected] with the steps to reproduce, the impact, and anything needed to verify it
  • We acknowledge within 2 business days
  • We give a triage decision and a severity within 10 business days
  • We tell you when it is fixed, and we credit you publicly if you want to be credited
  • Banrox does not currently run a paid bug bounty. We will say so up front rather than imply a reward that does not exist

6. Law Enforcement and Legal Requests

We require valid legal process. We review every request for scope and legal sufficiency, we push back on overbroad requests, and we produce the minimum responsive information. Where we are permitted to tell the affected person, we do, and we will delay production where lawful to give that person a chance to object. We do not give any agency direct or bulk access to member data.

7. Contact

Security reports: [email protected]. Suspected fraud on your account: call (888) 888-6401 immediately and then email [email protected] so there is a written record with a timestamp.

Call Us
Customer Service: (888) 888-6401
Location
40 N Altadena Dr Ste 105
Pasadena, CA 91107

Get Your Full Report

We will save this calculation to your Banrox record so you can pick it up later.

Success!

Your calculation has been saved.