Frequently Asked Questions
We employ industry-standard security controls, such as cryptography, to protect the personal information submitted to us, both during transmission and once we receive it. We also restrict access to protect you against fraud.
SuperMoney stores and processes user information using secure servers located only in the United States. This information is protected by physical, electronic and procedural safeguards in compliance with applicable US federal and state regulations.
After SuperMoney receives information, it is stored on a secure server that resides behind firewalls and data encryption designed to block unauthorized access from outside of the Company. Secure data transmissions help ensure that information remains confidential and we utilize 256 bit Secure Socket Layer encryption to transmit information. SuperMoney has also established physical, electronic and procedural safeguards in place to prevent access to personal information by employees except for purposes that are required to fulfill their job responsibilities.
SuperMoney does not store payment or related personal data at its office. Instead of storing payment information on company systems, SuperMoney stores payment or related personal data in PCI-compliant and PA-DSS certified data centers.
Remember, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You can help to maintain the security of your online transactions by not sharing your personal information with anyone and choose passwords that are difficult for others to guess and that don’t use personal information such as your birth date, address, or pet’s name. If you notice anything suspicious, please contact us immediately.
Here are a few things we recommend for keeping your info safe — with us, and in general.
For starters, make your password tough to guess. Mix up numbers, letters and special characters when you can. Make sure you never share it with anybody. And never reuse your SuperMoney account password on any other site.
We also recommend using virus protection, firewalls, and password managers. Make sure you never install programs from unfamiliar people or companies, or from suspicious emails. For any programs you install, apply all security updates. These steps will help protect you against identity theft and phishing attempts.
SuperMoney takes the security of its data and that of its clients and customers seriously and ensures that only necessary and fully vetted personnel are given access to that data.
All SuperMoney employees and contractors undergo background checks in accordance with applicable law and industry best practices.
Non-Disclosure Agreements are signed by all employees, contractors, and others who have a need to access sensitive data or information stored on company servers.
We embed the culture of security into our business by conducting employee security training & testing using current and emerging techniques.
All development projects at SuperMoney, including support services, follow secure development lifecycle principles.
All development of new products, tools, and services, and major changes to existing ones, undergo a design review to ensure security requirements are incorporated into the proposed development.
SuperMoney deploys third-party penetration testing and vulnerability scanning of all production and Internet-facing systems on a regular basis.
We perform penetration testing both by internal security engineers and external penetration testing companies on new systems and products or major changes to existing systems, services, and products.
SuperMoney leverages the native physical and network security features of its cloud services and relies on cloud providers to maintain the infrastructure, services, and physical access policies and procedures.
All data is also encrypted at rest and in transmission to prevent any unauthorized access and prevent data breaches. Our entire platform is also continuously monitored by dedicated, highly trained data security personnel.
Business client and consumer data protection complies with SOC 2 Type II standards to encrypt data in transit and at rest, ensuring customer and company data/sensitive information is protected at all times.
We implement role-based access controls and the principles of least-privileged access, and review revoke access as needed.
SuperMoney is committed to providing secure products and services and to safely and easily manage the digital identities of our users. Our independent certifications provide assurance of SuperMoney’s dedication to our customers by regularly assessing and validating the protections and effective security practices SuperMoney has in place.
SOC 2 Type II
SuperMoney has successfully completed the AICPA Service Organization Control (SOC) 2 Type II audit. The audit confirms that SuperMoney’s information security practices, policies, procedures, and operations meet the SOC 2 standards for security.
SuperMoney, was audited by Prescient Assurance, a leader in security and compliance certifications for B2B, SAAS companies worldwide. Prescient Assurance is a registered public accounting in the US and Canada that provides risk management and assurance services which include but are not limited to SOC 2, PCI, ISO, NIST, GDPR, CCPA, HIPAA, CSA STAR, etc. For more information about Prescient Assurance, you may reach out them at email@example.com
An unqualified opinion on a SOC 2 Type II audit report demonstrates to SuperMoney’s current and future customers that we manage their data with the highest standards of security and compliance.
Customers and prospects can request access to the audit report after the requestor signs an NDA. Please fill out the form here to request a SOC 2 report and accept NDA terms.