Security
How Determinds approaches security in the systems we design, build, and maintain, and how to report a vulnerability.
In short
Updated
Determinds designs the access model, audit trail, and data boundaries before the first screen, builds systems that run inside PCI DSS environments and to HIPAA standards, and welcomes vulnerability reports at info@determinds.com.
01
How we build
Many of our clients are banks, healthcare providers, and government bodies, where security is a core requirement from the start. On every engagement we design the parts that are hardest to add later before the first screen: who can see and change what, the audit trail, how long data is kept, and how a record is corrected.
Our systems run inside the environments our clients require, including on-premise and inside secured government locations, and we deliver them fully documented so a client’s own team can run them with confidence.
02
Security and compliance record
| Core banking integrations | 2, in production |
|---|---|
| D-PAY processing core | PCI DSS Level 1 and SOC 2 Type II through Visa Acceptance Solutions |
| Certification position | Determinds is the technology provider, not the certified entity. Certification sits with the financial institution, as it does with any technology vendor. Our systems operate inside our clients’ compliant environments. On D-PAY, the processing core is PCI DSS Level 1 and SOC 2 Type II through Visa Acceptance Solutions, and the bank remains acquirer of record under its own licence. |
| Healthcare | Systems built to HIPAA standards. No third-party attestation has been carried out. |
03
Standards and certifications
Where a project calls for a standard, such as HIPAA in healthcare, we build to it and state it clearly. Certifications and attestations belong to the organizations that hold them. If your procurement process requires a specific certification, our team will confirm our position at the start of the engagement.
04
This website
The site is served over HTTPS. Its content management system is open only to authenticated members of our team, and the content and inquiries it holds are stored with managed providers. How we handle personal information is described in our Privacy policy.
05
Reporting a vulnerability
If you believe you have found a security vulnerability in this website or in a Determinds product, email info@determinds.com with “Security” in the subject line. Please include what you found, where, and the steps to reproduce it.
We ask that you:
- give us a reasonable time to fix the issue before disclosing it publicly
- access only what you need to demonstrate the issue, and do not view, change, or delete other people’s data
- do not degrade the service, for example with denial-of-service testing, and do not use social engineering or physical attacks
We aim to acknowledge reports and to keep you informed as we investigate. We do not intend to take legal action against research carried out in good faith that follows these rules. This does not permit testing of systems that belong to our clients or to anyone else, and we reserve our rights where these rules are not followed. We do not currently offer rewards for reports.