Back home
Platinum FinancePlatinum Finance

Security & Trust

This page is maintained by Platinum Finance to answer common security and privacy questions about our platform. It describes the controls we have enabled today and the responsibilities we share with you. It is not an independent certification, audit report, or legal contract.

Access & authentication

Access to banking features requires a verified identity, completed KYC review, and explicit internal approval. Staff and owner portals use separate lanes and additional one-time passcode checks. All sessions enforce a five-minute idle timeout.

Platform & hosting

The application is hosted on Lovable Cloud. The backend uses Row-Level Security, least-privilege grants, signed webhooks, and strict Content-Security-Policy headers. Production readiness is checked by an automated preflight before traffic is served.

Data collection and use

We collect identity and contact details, device and transaction data needed to provide the service, and audit logs for fraud prevention and compliance. Data is not sold to third parties.

Sub-processors and integrations

We rely on Lovable Cloud for database, authentication, and hosting, and on integrated providers for KYC/identity verification and messaging. A full list is available on request.

Cookies and analytics

We use strictly necessary session cookies. We do not use third-party advertising cookies or cross-site trackers. Any analytics are first-party and anonymised.

Retention and deletion

We keep account and transaction data for as long as required by law and by our regulatory obligations. If you want to close your account or exercise a privacy right, contact us at the address below.

Vulnerability disclosure

If you discover a security issue, please report it privately. Do not exploit it or disclose it publicly until we have had a reasonable time to respond.

Security contact

Email: security@platinumfinance.app

Security page: platinumfinance.app/security

Shared responsibility

We secure the platform, enforce access controls, and monitor for abuse. You are responsible for keeping your sign-in credentials and access codes secret, using a strong device passcode, and promptly reporting loss or suspected misuse.