Security and Compliance

Our Commitment to Security, Compliance, and Risk Management

Security Overview

Isp Flash is committed to maintaining the highest standards of security for our Platform and user data. We implement comprehensive security measures to protect against unauthorized access, data breaches, and other security threats.

Technical Security Measures

Encryption

All data transmitted between users and our Platform is encrypted using industry-standard TLS/SSL protocols. Sensitive data at rest is encrypted using strong encryption algorithms.

Secure Infrastructure

Our infrastructure is hosted on enterprise-grade secure servers with multiple layers of security controls, including firewalls, intrusion detection systems, and regular security audits.

Access Controls

We implement strict access controls, including multi-factor authentication (MFA) for administrative access, role-based access controls, and regular access reviews.

Monitoring and Logging

We maintain comprehensive logging and monitoring systems to detect and respond to security incidents in real-time. All security events are logged and regularly reviewed.

Regular Updates

We regularly update our systems, applications, and dependencies to address security vulnerabilities and apply security patches promptly.

Compliance

Anti-Money Laundering (AML) and Know Your Customer (KYC)

Isp Flash implements AML and KYC procedures in accordance with applicable laws and regulations. We perform simplified identity verification (low KYC), in accordance with the rules and recommendations of the legal entity/enabled fintech that we use for operations in Brazil. We may require users to provide identification documents and other information to verify their identity and comply with regulatory requirements, always respecting the standards established by our partner fintech.

Data Protection Compliance

We comply with applicable data protection laws, including:

  • GDPR (General Data Protection Regulation) for users in the European Economic Area
  • LGPD (General Data Protection Law) for users in Brazil
  • Other applicable data protection laws in jurisdictions where we operate

Regulatory Compliance

As a technology platform headquartered in Seychelles, we operate in compliance with:

  • Laws and regulations of Seychelles
  • International standards and best practices
  • Brazilian regulations when interacting with Brazilian users and PIX services

Risk Management

Operational Risks

We maintain comprehensive risk management procedures to identify, assess, and mitigate operational risks, including technical failures, service interruptions, and security threats.

Financial Risks

Important: Isp Flash is NOT a bank or financial institution. We do NOT:

  • Accept deposits or hold user funds
  • Provide banking services
  • Act as a custodian of funds
  • Guarantee financial returns or investment opportunities

Users should be aware of the risks associated with digital assets, cryptocurrencies, and payment services, including market volatility, technological risks, and regulatory changes.

Compliance Risks

We continuously monitor regulatory developments and update our compliance procedures to ensure ongoing compliance with applicable laws and regulations.

Incident Response

We maintain an incident response plan to promptly address security incidents, data breaches, and other security-related events. In the event of a security incident affecting user data, we will:

  • Investigate the incident promptly
  • Take appropriate corrective actions
  • Notify affected users and relevant authorities as required by law
  • Implement measures to prevent future incidents

User Responsibilities

Users play an important role in maintaining security. Users are responsible for:

  • Maintaining the confidentiality of their account credentials
  • Using strong, unique passwords
  • Enabling multi-factor authentication when available
  • Reporting suspicious activities or security concerns immediately
  • Keeping their devices and software updated
  • Not sharing account credentials with third parties

Third-Party Services

We may use third-party services and providers for certain aspects of our Platform. We carefully select and monitor these providers to ensure they meet our security and compliance standards.

Special Refund Mechanism (MED) - Brazilian Central Bank

For Brazilian users, the Brazilian Central Bank provides a Special Refund Mechanism (MED) for unauthorized transactions. If you believe you have been a victim of an unauthorized transaction, you can request a refund through this mechanism.

Learn more about MED (Special Refund Mechanism)

Security Contact

If you have security concerns, questions, or need to report a security incident, please contact our security team immediately.

For general inquiries, please visit our