Compliance

How ISB meets its regulatory and security obligations.

Standards and frameworks

ISB aligns its policies and operations with the following frameworks. Reports are available to business customers on request.

PCI DSS

Card data is handled in line with the Payment Card Industry Data Security Standard. Card numbers are masked in the interface and virtual cards can be frozen at any time.

GDPR

We process personal data lawfully and only for stated purposes. You can request access to, correction of, or deletion of your data by contacting our data protection team.

SOC 2

Our controls for security, availability and confidentiality are reviewed by independent auditors each year.

ISO 27001

Our information security management system covers how we manage risk, access, suppliers and incidents.

Responsible disclosure

If you believe you have found a security issue affecting ISB, please tell us at security@isb.example. Include enough detail for us to reproduce it. We acknowledge reports promptly and keep you informed while we investigate.

Incident response

We maintain a documented incident response plan with named owners, escalation paths and communication templates. If an incident affects your data, we will notify you and the relevant authorities within the timeframes required by law.

Complaints

If you are unhappy with our service, contact customer care first. If we cannot resolve your complaint, you may refer it to the relevant financial ombudsman.