Trust

Security

Last updated 16 July 2026 · How we protect your data

Security is core to what Deposiq does: we sit at the moment money and trust first change hands. This page describes, in plain English, how we protect your data.

Hosting in the EU

The Service runs on dedicated infrastructure hosted in the European Union (Hetzner, Germany/Finland). Data is not transferred outside the EU/EEA.

Encryption

All traffic is encrypted in transit over TLS/HTTPS, with HSTS enforced. Data is encrypted at rest, and backups are encrypted.

Authentication & access

  • Passwords are stored hashed, never in plain text.
  • Administrative access is protected with two-factor authentication (TOTP).
  • Access follows the principle of least privilege; new accounts pass an approval gate.
  • Rate limiting, a firewall and fail2ban protect against automated abuse.

Payments

Deposiq never stores card numbers and never holds your funds. Card deposits are processed by Stripe or Mollie on your own connected account; PCI-DSS obligations for card data are met by these certified providers.

Evidence integrity

Every photo or document attached to a deposit is fingerprinted with SHA-256, and every action is timestamped in an audit trail — so evidence can be justified in a dispute and cannot be quietly altered afterwards.

Backups & resilience

Data is backed up regularly to encrypted, off-site storage, so it can be restored after an incident.

Responsible disclosure

If you believe you have found a security vulnerability, please email security@deposiq.com. We welcome good-faith reports and will respond promptly. Please do not access data that is not yours or disrupt the Service while testing.

No system can be guaranteed 100% secure. We continuously review and improve our measures, and this page reflects our current practices.