Platform Developers Docs API Network Security Roadmap Contact
#NeverBeenHacked · Year 16

Security as a prerequisite.

16 consecutive years operating with zero successful security breaches. We optimise for the boring kind of safe - the kind that doesn't make headlines.

Track record

The numbers we care about.

22+
Years operating
0
Successful breaches
100%
Funds in escrow
<15m
SEV-1 response
Defence in depth

Layered, not relying on one thing.

🔒

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest. Database column-level encryption for sensitive fields. Keys rotated on a published schedule.

🔑

ECDSA-signed boundaries

Cross-node and high-value endpoints require ECDSA signatures. Public keys live in a signed federation registry; we verify on every call.

💰

Escrow as default

Every paid task is funded into escrow at creation. There's no scenario where work is delivered and the buyer disappears with the money.

🛡

Tamper-detected nodes

Every federation peer publishes an RSA-signed health beacon. Tampering with the addon binary suspends the node automatically.

🧱

WAF + rate limits

Cloudflare WAF rules tuned to PHP/MySQL injection patterns. Per-account and per-IP rate limits. Anomaly alerts to oncall in seconds.

🧪

Annual external pentest

Independent third-party penetration test every calendar year. Most recent report available to enterprise customers under NDA.

Compliance

The frameworks we operate under.

GDPR
EU controller. DPA + DPO available.
ISO 27032
Cybersecurity governance baseline.
PCI-DSS
SAQ-A scoped via Stripe.
SOC 2 Type II
In progress, attestation expected Q4 2026.
CCPA
California consumer rights honoured.
DAC7
EU platform-economy reporting.
COPPA
Under-18 accounts blocked at signup.
eIDAS
Compatible identity verification.
Disclosure

Found something? Tell us.

We treat every report as serious until evidence says otherwise. Our acknowledgement window is 24 hours; triage within 72 hours; reward (if eligible) within 14 days of confirmation.

  • Email security@internetivo.com - PGP key fingerprint 4F2A 88B1 09EC 31A7 ….
  • Or use the bug bounty form if your finding falls under the published scope.
  • Please don't disclose publicly until we've shipped a fix. Coordinated disclosure is rewarded.