Skip to content

Security

Security

This page describes the security principles and practices applied to Rampay's website and product design. It does not describe certifications, audits or attestations, and none should be inferred.

No certification, audit outcome, attestation or third-party security accreditation is claimed on this website.

Website

Website security principles

Security principles are applied to how the service is designed, built and operated.

Encryption in transit

Traffic to and from Rampay web surfaces is designed to be served over HTTPS using modern transport encryption.

Access control

Access to systems and data is intended to be granted on a least-privilege basis and reviewed as part of operational practice.

Environment separation

Development, review and production environments are intended to be separated with controlled promotion between them.

Secret management

Credentials and sensitive configuration values are intended to be held in managed secret storage rather than in source code.

Dependency hygiene

Third-party dependencies are kept under review, with updates applied as part of ongoing maintenance.

Logging discipline

Operational logging is designed to avoid recording sensitive submitted content unnecessarily.

Website hardening

Web application controls

The public website applies a set of hardening measures appropriate for an informational financial-services site.

  • HTTPS-only delivery of the public website
  • Security response headers applied at the application layer
  • Content-Security-Policy applied to constrain loadable resources
  • Strict referrer policy on outbound navigation
  • Framing restrictions to reduce clickjacking exposure
  • MIME-type sniffing disabled via nosniff
  • Restrictive permissions policy for browser features not used by the site

Data handling

Data protection principles

The website collects only what is needed to handle your enquiry or transaction, and handles it accordingly.

Data minimisation

Information collected through this website is intended to be limited to what is needed for your enquiry or transaction.

Purpose limitation

Information you submit is used for the purpose of handling your enquiry or transaction.

Input validation

Submissions are validated on both the client and the server, with length and format constraints applied.

Abuse controls

Enquiry and transaction submissions are subject to rate limiting, with abuse-resistance treated as an ongoing operational principle.

Safe error handling

Error responses are designed to avoid exposing internal system details.

Retention

Information is intended to be retained only as long as necessary for the purpose for which it was provided.

Operations

Operational security practices

Operational discipline is what keeps controls effective over time.

  • Change review before production deployment
  • Monitoring of application errors and availability signals
  • Defined internal escalation for suspected security issues
  • Incident response principles covering assessment, containment and review
  • Periodic review of access, dependencies and configuration
  • Vulnerability reports handled through the contact channel on this website

Responsible disclosure

Reporting a potential vulnerability

If you believe you have identified a security issue affecting this website, we would like to hear from you.

Please contact us through the enquiry form. Include enough information to reproduce or understand the issue, and avoid actions that could affect the availability of the service or the privacy of others.

We ask that potential issues are not publicly disclosed before we have had a reasonable opportunity to assess and respond.

Third-party service providers

Shared security boundaries

Your transaction may involve third-party service providers for payment, verification or digital asset transfer components.

Where third-party service providers participate in your transaction, those providers maintain responsibility for the systems and services they operate. Rampay does not represent that it controls the full security environment of every third-party service involved in a transaction.

This page describes intended principles and practices. It is provided for information purposes only, is not a warranty or guarantee of security outcomes, and does not constitute a representation of certification or regulatory status.