Security

What is actually in place.

Most security pages list certifications a company is working towards as though it already held them. This one lists what exists today, and separately, what does not.

In place

TLS in transit
Every request is served over HTTPS, with certificates issued and renewed by the platform.
Two-factor authentication
TOTP with recovery codes, on both merchant and publisher accounts.
Audit logging
Configuration and data-access events are written to an append-only audit log.
Immutable financial ledger
Commission and payout entries cannot be edited or deleted. Corrections post as reversing entries, so the history stays reconstructable.
Hashed customer identifiers
Conversion matching uses hashed email identifiers rather than storing raw addresses for attribution.
Idempotent conversion API
A duplicate webhook delivery cannot double-credit a commission.
Verified webhooks
Inbound Stripe events are checked against the endpoint signing secret; invalid signatures are rejected.
Bot filtering on clicks
Click tracking screens known bot traffic before it reaches attribution.
UK/EU hosting
Application and database run in London (eu-west-2).

Not in place

If any of these is a hard requirement for you, this is not the right platform yet. Better you know now than after onboarding.

SOC 2 Type II
Not started. This page will say so when it changes.
ISO 27001
Not started.
Third-party penetration test
Not yet commissioned.
SSO / SAML
Not built. Accounts use a password plus TOTP.
Contractual incident-response SLA
None offered. We will not promise a response time we cannot staff.

Found something we should fix?

Report it to security@goreign.co. We will confirm receipt and tell you what we did about it.