DATA SECURITY & TRUST
PUBLIC SECURITY LEADERSHIP

Security that has
an accountable owner.

DataCred operates a security program built around clear responsibility, controlled access, continuous monitoring, and disciplined response across the systems we own or explicitly control.

ACCOUNTABLE SECURITY LEADER

Isacc Lara Gonzalez

Founder & CEO · Security Lead

Responsible for information security oversight, vulnerability management, incident response, and security governance across DataCred.

PUBLIC SECURITY LEADERSHIP
SECURITY PROGRAM

Defined scope. Clear boundaries.

Security testing and validation are limited to DataCred systems or environments where DataCred has explicit authorization.

ApplicationsWeb, iOS and Android
PlatformAPIs and internal services
InfrastructureCloud production environment
OperationsAdministrative and security workflows
OPERATING MODEL

Security is part of how we operate.

Our program favors practical controls, traceability, and fast remediation over decorative compliance language.

01

Executive accountability

Security ownership is explicit. Material security decisions, remediation priorities, and incident handling have an accountable executive owner.

02

Vulnerability management

We identify, assess, prioritize, and remediate vulnerabilities affecting DataCred-owned or explicitly controlled systems, followed by patch validation where appropriate.

03

Access & infrastructure

Production access is restricted, secrets are centrally managed, transport is encrypted, and operational changes follow controlled deployment procedures.

04

Monitoring & response

Operational health, service failures, and relevant security events are monitored so the team can investigate, contain, remediate, and review incidents.

CORE PRINCIPLES

Built for a financial platform.

01

Least privilege

Access is limited to what is required for a role or service.

02

Data minimization

Security processes avoid collecting or exposing unnecessary sensitive data.

03

Traceability

Operational actions and material changes are designed to leave an auditable trail.

04

Responsible testing

Security testing stays inside authorized boundaries.

OPERATING ENTITY

DataCred Tech S.A.S.

DataCred Tech S.A.S. is the current operating entity identified in DataCred’s public legal and trust materials. This security page describes the security leadership and operating program for the DataCred product and systems.

Nothing on this page should be interpreted as a claim of ISO 27001, SOC 2, or another certification unless DataCred explicitly publishes that certification.

SECURITY CONTACT

Report a security concern.

If you believe you have identified a security issue involving DataCred, contact us with enough detail to reproduce and investigate it. Do not send passwords, access tokens, private keys, or unnecessary personal data.