Legal Policies and Compliance Information
Introduction
Terms of Service
Prohibited
Privacy
Information Security
Crypto Risk Summary
Cookies
Complaints
Information Security
Introduction
Terms of Service
Prohibited
Privacy
Information Security
Crypto Risk Summary
Cookies
Complaints

Information Security

On this page
Purpose
Scope
Statement
What We Will Never Do
Incidents

Purpose

This policy details Jigzo’s unwavering commitment to protecting the confidentiality, integrity, and availability of our information assets. It establishes a robust framework of principles and responsibilities to guard against cyber threats and ensure the secure operation of our systems. Our aim is to build and maintain a secure environment that inspires trust among our customers and partners.

Scope

While this is an internal policy that applies to all Jigzo employees, contractors, and third-party service providers, we share it publicly to provide transparency into our security practices. It covers all information systems, data, and processes used to deliver our services, demonstrating our dedication to safeguarding customer information and maintaining a resilient platform.

Statement

Jigzo Limited recognises that the confidentiality, integrity and availability of information are critical to its operation and to the trust of its clients. The following controls apply.

Access. Access to systems and data is granted on the principle of least privilege, individually named, reviewed quarterly, and removed on the day a person leaves. Privileged access is separately approved and reviewed monthly.

Authentication. Multi-factor authentication is mandatory for all client access to the platform and for all personnel access to systems holding client data. Authenticator applications are the preferred method. Sensitive actions require additional verification.

Encryption. Data is encrypted in transit using current protocols, and at rest.

Credentials. Credentials and access keys are held in dedicated secrets management. They are never stored in plain text, never held in code or configuration under version control, and are rotated on personnel change, on suspected compromise, and at least annually.

Vulnerability management. Application code and dependencies are scanned continuously for known vulnerabilities. Infrastructure and system logs are monitored with alerting. Identified vulnerabilities are remediated to documented timescales, with critical vulnerabilities addressed as a priority.

Independent testing. The platform is subject to independent penetration testing at least annually, and following any material change. Findings are tracked to closure.

Hosting and resilience. The platform is hosted in the United Kingdom on mirrored infrastructure, with automated backups. Restoration is tested annually.

Change control. Changes affecting client data or a control are approved before release, tested outside production, and reversible.

People. Personnel are trained on information security before being granted access and at least annually, including recognition of phishing and social engineering. Simulated phishing exercises are conducted.

Business continuity. Continuity and recovery arrangements are documented, tested and reviewed annually.

What We Will Never Do

We will never ask you for your password or a full authentication code, in any channel, for any reason. If someone claiming to be from Jigzo does, it is not us. Tell us immediately.

Incidents

Security incidents are managed under our incident response procedures. Where an incident affects your data or your ability to use the service, we will tell you. Where a personal data breach meets the notification threshold, we notify the Information Commissioner's Office within 72 hours.

Updated at:
February 24, 2026
On this page
Purpose
Scope
Statement
What We Will Never Do
Incidents
Contact us
Jigzo Limited is a financial technology company registered in England and Wales (no. 12014461).

Jigzo is not a bank. Client funds are held in individually designated accounts with an FCA-authorised payment institution and are safeguarded by that institution in accordance with its regulatory obligations. Accounts provided through the platform are payment accounts, not bank accounts, and are not covered by the Financial Services Compensation Scheme.
Jigzo — The Managed Banking Experience.
© Jigzo Limited, All Rights Reserved