Compliance
How ISB meets its regulatory and security obligations.
Standards and frameworks
ISB aligns its policies and operations with the following frameworks. Reports are available to business customers on request.
PCI DSS
Card data is handled in line with the Payment Card Industry Data Security Standard. Card numbers are masked in the interface and virtual cards can be frozen at any time.
GDPR
We process personal data lawfully and only for stated purposes. You can request access to, correction of, or deletion of your data by contacting our data protection team.
SOC 2
Our controls for security, availability and confidentiality are reviewed by independent auditors each year.
ISO 27001
Our information security management system covers how we manage risk, access, suppliers and incidents.
Responsible disclosure
If you believe you have found a security issue affecting ISB, please tell us at security@isb.example. Include enough detail for us to reproduce it. We acknowledge reports promptly and keep you informed while we investigate.
Incident response
We maintain a documented incident response plan with named owners, escalation paths and communication templates. If an incident affects your data, we will notify you and the relevant authorities within the timeframes required by law.
Complaints
If you are unhappy with our service, contact customer care first. If we cannot resolve your complaint, you may refer it to the relevant financial ombudsman.