Security

Money and data —
protected.

Every payment is recorded to the last cent and checked against bank statements daily. Card data never touches our servers. And if something goes wrong, the payment stops and a person steps in. That's how it should be by default.

Encrypted by default · cards never stored · access is yours only
Card payment
Card number
•••• •••• •••• 4210
Expiry
••/••
CVC
•••
Pay 10 000 ₽
Card data goes straight to the bank
We never see the card number
Sign-in confirmed
+ code from your app
Daily reconciliation
everything adds up
Money

Every payment accounted for. To the last cent.

Inside is double-entry bookkeeping, like in a bank: every amount shows its path from payment to payout, and everything adds up every single day.

Recorded to the cent

Every payment, conversion and payout is its own record that can't be erased or rewritten. Totals are computed from the records, so the number in your dashboard is always honest.

More detail+

A balance isn't stored "somewhere in a database" — it is recalculated from real operations every time. There is simply nowhere for an error to hide.

Client money held apart

Client funds sit with licensed partners, separately from company money, and are never mixed.

More detail+

Every day we check our records against the partners' statements. A mismatch of even one cent is a top-priority incident for our team — not a line in a report.

A payout can't get lost

Before a payout, the amount is reserved so it can't be spent twice. If a bank doesn't respond, the operation stops and a person steps in — never a blind retry.

More detail+

Every step of a payout can be safely repeated or rolled back. After any failure the system continues from exactly where it stopped.

Data

Data we don't need, we simply don't have.

The best way to protect data is to not keep anything extra. What we do keep is encrypted; every access to it is recorded.

We never store cards

The buyer enters the card number on the bank's protected page, built to the PCI DSS standard. It never reaches our servers.

More detail+

We run in the minimal PCI DSS scope: the full card number and the CVC code are handled by a certified bank partner. Card data can't be stolen from us — we simply don't have it.

Everything encrypted

Data is encrypted in transit and at rest. Partner access keys live in a separate protected vault.

More detail+

Secrets are stored envelope-style: the key that encrypts the data is itself encrypted with a master key. Keys never sit anywhere in the open — and never end up in logs.

Access is yours only

Signing in to the dashboard requires confirmation. Inside our team, access is role-based: everyone sees only what their job needs.

More detail+

Every time an employee touches client data, it is written to a log that can't be edited. Sensitive actions require a second person's confirmation.

Your documents don't wander

Documents you upload for verification are encrypted and shared with a partner only with your consent — and only as much as needed.

More detail+

The minimum principle applies: a partner receives only the fields it is required to check. Retention is limited, and data is deleted on request — within what the law requires us to keep.

The honest scenario

If something goes wrong.

Reliability isn't "we never fail". It's what happens in the first minutes when something does.

The payment stops itself

A doubtful or stuck operation doesn't push through "somehow" — it freezes in a safe state.

A person takes over

An engineer sees the operation's full history to the cent and decides what happens next. No blind retries.

You hear it from us first

Component status is public on the status page, and support answers 24/7 — in plain words.

Questions about security?

Ask us directly — emails to security@ are answered by engineers, not scripts. Found a vulnerability? Write to us first.

security@freeconomy.shop — questions and responsible disclosure