Platform Developers Docs API Network Security Roadmap Contact
#NeverBeenHacked ยท Year 16

Security as a prerequisite.

16 consecutive years operating with zero successful security breaches. We optimise for the boring kind of safe - the kind that doesn't make headlines.

Track record

The numbers we care about.

22+
Years operating
0
Successful breaches
100%
Funds in escrow
<15m
SEV-1 response
Defence in depth

Layered, not relying on one thing.

๐Ÿ”’

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest. Database column-level encryption for sensitive fields. Keys rotated on a published schedule.

๐Ÿ”‘

ECDSA-signed boundaries

Cross-node and high-value endpoints require ECDSA signatures. Public keys live in a signed federation registry; we verify on every call.

๐Ÿ’ฐ

Escrow as default

Every paid task is funded into escrow at creation. There's no scenario where work is delivered and the buyer disappears with the money.

๐Ÿ›ก

Tamper-detected nodes

Every federation peer publishes an RSA-signed health beacon. Tampering with the addon binary suspends the node automatically.

๐Ÿงฑ

WAF + rate limits

Cloudflare WAF rules tuned to PHP/MySQL injection patterns. Per-account and per-IP rate limits. Anomaly alerts to oncall in seconds.

๐Ÿงช

Annual external pentest

Independent third-party penetration test every calendar year. Most recent report available to enterprise customers under NDA.

Compliance

The frameworks we operate under.

GDPR
EU controller. DPA + DPO available.
ISO 27032
Cybersecurity governance baseline.
PCI-DSS
SAQ-A scoped via Stripe.
SOC 2 Type II
In progress, attestation expected Q4 2026.
CCPA
California consumer rights honoured.
DAC7
EU platform-economy reporting.
COPPA
Under-18 accounts blocked at signup.
eIDAS
Compatible identity verification.
Disclosure

Found something? Tell us.

We treat every report as serious until evidence says otherwise. Our acknowledgement window is 24 hours; triage within 72 hours; reward (if eligible) within 14 days of confirmation.

  • Email security@internetivo.com - PGP key fingerprint 4F2A 88B1 09EC 31A7 โ€ฆ.
  • Or use the bug bounty form if your finding falls under the published scope.
  • Please don't disclose publicly until we've shipped a fix. Coordinated disclosure is rewarded.