BankConnectorSecurity Policy · v1.0

Security Policy

v1.0Last updated 8 July 2026. This Policy forms part of the Agreement and describes the security measures we commit to for production services. It states what is built and operating today; planned items are marked as such and become commitments when achieved.

1Architecture and isolation

2Encryption and key custody

3Access control and authentication

4Integrity and auditability

5Operations and continuity

6Secure development

7Incident response

8Certifications and assurance

9Customer-side controls

Security is shared. Customers are expected to: enforce MFA for administrators and approvers; use role separation and approval policies appropriate to their risk; protect API keys and rotate them on suspicion of compromise; verify webhook signatures; keep user lists current and disable departed personnel promptly; and report suspected compromise without undue delay.

BankConnector ApS · bankconnector.com/legalBC-POL-SEC-1.0