Custody
Client assets are held 1:1 with regulated, bankruptcy-remote custodians and are never commingled with operating funds.
We designed Sterling for the security review, not around it. Every control below maps to a recognized framework, and the evidence is available under NDA. No hand-waving, no exceptions.
Talk to our security team
Client assets are held 1:1 with regulated, bankruptcy-remote custodians and are never commingled with operating funds.
AES-256 at rest and TLS 1.3 in transit, with keys held in FIPS 140-2 validated hardware security modules.
SSO, SCIM provisioning, granular roles, and mandatory dual approval on every movement of money.
24/7 anomaly detection, immutable audit logs, and real-time alerting on privileged actions.
Multi-region redundancy, point-in-time backups, and a tested recovery plan with a four-hour RTO.
Annual third-party penetration tests and a standing bug bounty program, with summaries shared under NDA.
99.99%
Platform availability SLA
< 4h
Disaster recovery objective
0
Reportable breaches to date
24/7
Security operations coverage
Current reports are available to prospective customers under NDA through your account team.
SOC 2 Type II
Independently audited annually
PCI DSS Level 1
Highest merchant tier
ISO 27001
Information security management
GDPR & CCPA
Data processing agreements available
GLBA aligned
Safeguards for financial data
NIST CSF
Control framework mapping
Their security package answered our vendor questionnaire before we finished asking. Approval took days, not quarters.Reports, penetration test summaries, and our DPA are available under NDA. Start a review with our team.
Talk to our team