Skip to content
← Trust Centre

Information security

Our certification, how we describe our security posture, and how to report a vulnerability.

  • ISO 27001

Information security at dospay

Placeholder. This article was scaffolded when the Trust Centre launched. The substance below is accurate, but the wording is awaiting final review through the documentation review flow.

Certified information security management

DOS & Co. Ltd operates an information security management system certified to ISO/IEC 27001 (certificate number 00510). Certification means our security controls, risk management and governance are independently assessed against the international standard.

Our security posture

We describe our controls at posture level. We deliberately do not publish implementation detail:

  • Access to systems and data follows the principle of least privilege, with role-based access control and audit trails on sensitive activity.
  • Data is encrypted in transit and at rest.
  • Sensitive account information is stored separately from general records and revealed only under step-up authentication, with every reveal audited.
  • Our systems and infrastructure undergo regular penetration testing by independent external security specialists.
  • We maintain insurance cover appropriate to the nature and scale of the services we provide.

Reporting a vulnerability

If you believe you have found a security vulnerability in any of our services, please see our responsible disclosure policy.

Last reviewed 3 Aug 2026 · Version 1.0

Independent assurance

Professional Indemnity Insurance

DOS & Co. Ltd maintains insurance cover appropriate to the nature and scale of the services we provide.

Responsible disclosure policy

Placeholder. This article was scaffolded when the Trust Centre launched. The substance below is accurate, but the wording is awaiting final review through the documentation review flow.

Reporting a vulnerability

We welcome reports from security researchers and members of the public who believe they have found a vulnerability in any dospay or DOS & Co. service.

Please email support@dospay.co.uk with the subject line "Security disclosure", including enough detail for us to reproduce and assess the issue. We will acknowledge your report and keep you informed as we investigate.

What we ask of you

  • Give us a reasonable opportunity to investigate and remediate before any public disclosure.
  • Do not access, modify or retain data that is not yours; if personal data is exposed, stop and report it immediately.
  • Do not degrade our services (for example, denial-of-service testing) or use social engineering against our staff or customers.

What you can expect from us

  • Acknowledgement of your report and a good-faith, timely investigation.
  • We will not pursue legal action against research conducted in line with this policy.
  • Credit, where you would like it, once an issue is resolved.

A machine-readable pointer to this policy is published at /.well-known/security.txt.

Last reviewed 3 Aug 2026 · Version 1.0

Machine-readable disclosure details: /.well-known/security.txt

At a glance

FCA-authorised
FRN 1041318 · Financial Conduct Authority
ISO/IEC 27001
Certificate No. 00510 · UKAS-accredited (3core²)
Bank of England
All of our GBP funds are safeguarded, liquid and unencumbered, at the Bank of England through our banking technology partners.
FCA-Authorised
Authorised and regulated by the Financial Conduct Authority for the provision of payment services (FRN 1041318).
ISO 27001
Information security certified to ISO/IEC 27001 (certificate 00510).

Ask us anything about this

If you need something evidenced for your own compliance file, or want to talk to the people responsible, we will put you in touch.

Contact us

We answer regulatory and safeguarding questions directly.