Skip to main content
Super Save Protocol SSP Registry
Home About Us Services How It Works Leadership
Request access
SSP Registry
Home 01 About Us 02 Services 03 How It Works 04 Leadership 05
Request registry access
hello@supersaveprotocol.com
Mon–Fri, 09:00–18:00 GMT
All legal documents

Information Security Policy

Last updated · 11 August 2026 Effective · 11 August 2026 Version 1.0
On this page

On this page

  1. Governance
  2. Access control
  3. Data protection in transit and at rest
  4. Application security
  5. Logging and monitoring
  6. Resilience and continuity
  7. Personnel security
  8. Supplier security
  9. Testing
  10. Incident response

The registry holds the identifiers on which member institutions base financing decisions. This policy summarises the controls that protect it. Members carrying out security due diligence can request our detailed control documentation from security@supersaveprotocol.com.

01 Governance

  • A named individual is accountable for information security and reports to the board.
  • Security policies are reviewed at least annually, and after any material incident or architectural change.
  • Risk assessments are documented, owned and tracked to closure.
  • Security requirements are considered at design time for every new module — not bolted on before launch.

02 Access control

  • Role-based access control across twelve institutional roles, each with an explicit ability set.
  • Organisation scoping: a user sees their own institution's records and only the registry-wide fields the check requires.
  • Least privilege by default; elevation requires approval and is logged.
  • Two-factor authentication for registry accounts.
  • Password hashing with a modern one-way algorithm, enforced rotation, and lockout after repeated failed attempts.
  • Idle session timeout and session invalidation on password change.
  • Quarterly access reviews by member administrators, with our support.
  • Administrative access to production is restricted, individually attributed and logged.

03 Data protection in transit and at rest

  • TLS 1.2 or above for all connections, with modern cipher suites and HSTS.
  • Encryption at rest for databases, file storage and backups.
  • Document fingerprints computed with SHA-256; credentials never stored in reversible form.
  • Secrets held in a managed secret store, rotated on a defined schedule and on personnel change.

04 Application security

  • Parameterised database queries and output encoding as standard practice.
  • Cross-site request forgery tokens on every state-changing request.
  • Security headers including content type options, frame options and referrer policy.
  • Input validation server-side, never relying on client-side checks alone.
  • Dependency scanning with defined remediation timescales by severity.
  • Code review before merge; no direct changes to production.

05 Logging and monitoring

  • Append-only audit log capturing actor, organisation, role, action, timestamp and IP for every registry action.
  • Authentication events logged separately, including failures and lockouts.
  • Alerting on anomalous access patterns, privilege changes and bulk data access.
  • Logs protected against alteration and retained for seven years.

06 Resilience and continuity

  • Automated backups with encryption, held on a 35-day rolling window.
  • Restore testing on a defined schedule, with results recorded.
  • Documented recovery point and recovery time objectives, reviewed annually.
  • Business continuity and disaster recovery plans exercised at least annually.

07 Personnel security

  • Background checks proportionate to role, where lawful in the jurisdiction.
  • Confidentiality undertakings for all personnel and contractors.
  • Security and data protection training on joining and annually thereafter.
  • Access revoked on the day a person leaves or changes role.
  • Clear desk and device encryption requirements for anyone handling production data.

08 Supplier security

Every supplier with access to registry data is assessed before engagement and re-assessed periodically. Contracts include security obligations, breach notification and audit rights no less protective than those we owe Members. Current sub-processors are published at Sub-processors.

09 Testing

  • Independent penetration testing at least annually and after significant architectural change.
  • Findings triaged by severity with defined remediation timescales and tracked to closure.
  • A summary report is available to Members under confidentiality on request.
  • Vulnerability reports from external researchers are welcomed under the Responsible Disclosure Policy.

10 Incident response

  1. Detect and triage. Incidents are classified by severity within one hour of detection.
  2. Contain. Immediate action to limit impact, including suspending access where necessary.
  3. Notify. Affected Members are told without undue delay, and within 48 hours where personal data is involved. Supervisory authorities are notified within 72 hours where the threshold is met.
  4. Eradicate and recover. Root cause removed, service restored, integrity verified.
  5. Review. A blameless post-incident review with corrective actions owned and tracked.

Report a suspected incident to security@supersaveprotocol.com.

Questions about this document?

Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.

Super Save Protocol SSP Registry

A shared registry for customs authorities, banks, factoring companies and cheque cashers — so the same document can never be financed twice.

Super Save Protocol Ltd
207 Regent Street
London
W1B 3HH
United Kingdom
hello@supersaveprotocol.com

Company

  • Home
  • About Us
  • Services
  • How It Works
  • Leadership
  • Contact Us
  • Sitemap

Registry

  • Customs Registry
  • Bank Finance
  • Collateral Registry
  • Invoice Factoring
  • Cheque Verification

Legal

  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • GDPR Statement
  • Data Processing Agreement
  • Sub-processors
  • Data Retention

Policies

  • Acceptable Use
  • AML / KYC & Sanctions
  • Information Security
  • Responsible Disclosure
  • Service Level Agreement
  • Refund & Cancellation
  • Accessibility
  • All legal documents
© 2026 Super Save Protocol Ltd. All rights reserved. Privacy Terms Cookies Accessibility Registered in England & Wales · 17377995

Cookies on this site

We use strictly necessary cookies to keep the site working and secure. Analytics cookies are only set if you accept them. Read the Cookie Policy.