Trust center

One page for the questions your security team is about to ask.

Audits, posture, status, and a working inbox for vulnerability reports. Nothing behind a sales call you don't already need.

Certifications

Where we are on the audit calendar.

StandardStatusNotes
SOC 2 Type IAvailableIssued January 2026 by a Big-Four affiliated auditor. Available under NDA.
SOC 2 Type IIIn progressObservation window started February 2026. Report expected Q3 2026.
ISO 27001Targeted Q4 2026Stage 1 audit booked. ISMS scoped to production engineering.
PCI DSSNot applicableOpenSettle never handles cardholder data. Stablecoins only.
GDPR / UK GDPRCompliantDPA, SCCs, and UK Addendum available at /legal/dpa.
MiCA (EU)Out of scopeArchitectural posture documented at /legal/compliance.
Reporting

Found something? We want to know.

We operate a coordinated disclosure program. Reports are triaged within one business day. Critical findings on the smart-contract Router are eligible for our Immunefi-style bounty (up to $250,000).

Email
security@opensettle.example

PGP key fingerprint published in security.txt.

security.txt
/.well-known/security.txt

RFC 9116 disclosure metadata. Contact, expiry, policy.

Policy
Disclosure policy & safe harbor

Good-faith research is protected. No legal action against researchers who follow our policy.