- Encryption of sensitive data at rest using strong ciphers like AES, and encryption of all data in transit using TLS.
- All card data is tokenized and stored in PCI DSS Level 1 compliant vaults.
- Ongoing vulnerability scans powered by Dependabot, GCP Container Analysis, and cubic.
- Ongoing access reviews.
- Regular scheduled backups of all data.
- Logging and monitoring.
- All changes made to production systems are reviewed by an engineer other than the one who made the change.
- Secure coding training for all engineers.

