Security

Bank-grade security.
By default.

We use Stripe's enterprise infrastructure, cryptographic delivery proofs, and regulated financial institutions. Your money is never in our bank accounts.

How we protect you

Built on trusted foundations.

Powered by Stripe

Payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor trusted by Amazon, Google, and Shopify. We never touch or store your card details.

Funds held by regulated EMI

Stripe Technology Europe Ltd is an Electronic Money Institution (EMI) regulated by the Central Bank of Ireland. Your money is held in segregated accounts, not in Holdy's.

SHA-256 delivery proofs

Every delivery is cryptographically hashed and timestamped. If a dispute arises, we have immutable proof of what was delivered and when.

Verified sellers only

Every seller completes Stripe KYC verification before they can receive payments. Real identity, real bank account, verified by a regulated financial institution.

The technical stack

Enterprise-grade,
by design.

Encryption

TLS 1.3 everywhere

All data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. No unencrypted HTTP anywhere.

Access Control

Row-level security

Database access is locked down with row-level security. You can only see your own transactions — not even our engineers can access them without proper authorization.

Infrastructure

Hosted in EU

Primary data stored in EU data centers (Frankfurt). GDPR-compliant by default. Daily encrypted backups with 30-day retention.

Authentication

Secure by default

Passwords hashed with bcrypt. Email verification required. Rate limiting on every endpoint. Session tokens with strict expiration.

Fraud Prevention

Stripe Radar

Every transaction is screened by Stripe Radar using machine learning trained on billions of transactions across the Stripe network.

Audit

Activity logging

Every action is logged: deals created, payments made, disputes opened. Immutable audit trail for every transaction, queryable by you.

Compliance

Regulated.
Audited. Transparent.

GDPR compliant

Full GDPR compliance including right to access, rectification, and erasure. Clear data processing agreements with all our sub-processors. See our Privacy Policy.

AML/KYC verified

All sellers pass AML (Anti-Money Laundering) and KYC (Know Your Customer) checks via Stripe before they can receive payments. Identity verification, document checks, and ongoing monitoring.

PSD2 compliant

Full PSD2 compliance for European payment services. Strong Customer Authentication (SCA) enforced on all transactions through Stripe.

Dutch regulation

Operating as a Dutch entity (WebInstal, KvK 78581672), subject to Dutch consumer law and the Wwft (anti-money laundering act).

Responsible disclosure

Found a vulnerability?

We take security seriously. If you've found a security issue, please report it responsibly.

security@getholdy.com

Ready when
you are.

Enterprise-grade security for every deal, big or small.

Start your first deal