Security & Data Protection
Your security is ourshared responsibility.
FinBursa is built to institutional-grade security standards. Below you'll find what we do to protect your data — and what you can do to stay secure.
- ISO 27001 Certified
- SOC 2 Type I Completed
- GDPR Aligned
Your security checklist
Steps you can take to stay secure
Use Strong Authentication
- Choose a password with at least 12 characters, including letters, numbers, and symbols.
- 2-Factor Authentication (2FA) is enabled by default.
Stay Alert to Phishing & Social Engineering
- FinBursa will never ask for your password or private details via email or phone.
- Be cautious of unsolicited emails or messages pretending to be from FinBursa.
Keep Your Login Credentials Private
- Never share your FinBursa password or email password with anyone.
- If you experience login issues, reach out to our team through contact@finbursa.com
Verify You're on the Official FinBursa Website
- Always check that you are visiting https://www.finbursa.com
- Our website is secured with SSL/TLS encryption to protect your data from interception.
Watch Out for Fake Emails (Email Spoofing)
- Always verify that emails from FinBursa come from an @finbursa.com or @email.finbursa.com domain.
- Be cautious with emails that request sensitive information or contain urgent security warnings.
How FinBursa protects your data
Platform Security
ISO 27001 Certified
FinBursa is certified to ISO/IEC 27001:2022, the internationally recognized standard for information security management.
SOC 2 Type I Completed
FinBursa has completed its SOC 2 Type I examination, assessing the design of controls relevant to security. SOC 2 Type II is planned as the next stage of our assurance program.
GDPR-Aligned Data Protection Controls
Lawful-basis processes, Data Processing Agreements, Standard Contractual Clauses, and data-subject request workflows are maintained as part of FinBursa's data protection framework.
DDoS Protection & Web Application Security
Leading firewall and anti-DDoS systems help protect the platform against network and application-layer threats.
Regular Security Testing
Internal and third-party penetration tests are conducted regularly to identify and address potential vulnerabilities.
Vulnerability Management
Vulnerabilities are prioritized based on severity to ensure critical issues are addressed promptly and systematically.
Data Encryption
Data at rest is encrypted using AES-256. Data in transit is protected with TLS v1.2+.
Privacy Policy
FinBursa maintains a dedicated Privacy Policy governing how personal data is collected, used, and handled.
How FinBursa protects your data
Internal Security Measures
Employee Device Security
Industry-leading endpoint protection and anti-malware solutions are deployed across employee devices.
Access Controls
Single Sign-On (SSO), Multi-Factor Authentication (MFA), and least-privilege access principles govern access to internal systems.
Continuous Monitoring
Security Information & Event Management (SIEM) provides continuous visibility into platform activity and potential threats.
Backup & Disaster Recovery
Continuous backups are maintained across multiple secure locations to support data resilience and rapid recovery.
Responsible disclosure
Vulnerability Disclosure Policy
FinBursa believes effective disclosure of security vulnerabilities requires mutual trust, respect, and transparency between FinBursa and the security community.
FinBursa accepts vulnerability reports from independent security researchers, industry partners, vendors, customers, and consultants.
This policy applies to digital assets owned, operated, or maintained by FinBursa, including our public-facing websites.
Vulnerability reporting
Report a Vulnerability
FinBursa encourages security researchers to report suspected vulnerabilities affecting any asset owned, controlled, or operated by FinBursa using the form below.
The FinBursa Security team will acknowledge receipt, investigate the report, and take appropriate action toward resolution.