Security & trust

Security without the theatre.

We're building financial infrastructure. That comes with real obligations. Here is exactly what we do, where we cut corners (nowhere), and which partners hold which licenses.

The stack we trust.

Issuing

Lithic

Card issuance partner. SOC 2 Type II. The only viable Canadian API-first issuer at the volumes we operate.

Stablecoin

Bridge (Stripe)

USDB issuance with 1:1 reserve, monthly audits, regulated under US/EU frameworks.

CAD on-ramp

Paytrie

Canadian-licensed CAD ↔ stablecoin and CAD ↔ USD on-ramp.

Browser execution

Browserbase + Stagehand

Isolated, audited browser environments. Every government filing is recorded end-to-end.

Practices.

  • Data minimization.

    We collect what the regulator and the partner require. Nothing else. We do not sell or share data with third parties for advertising.

  • SOC 2 in progress.

    Type I gap analysis underway with a Big Four assessor. Type II target Q1 2027.

  • Encryption at rest and in transit.

    AES-256 at rest, TLS 1.3 in transit. Cardholder data tokenized at Lithic; never lives at Nimble & Cross.

  • Access control.

    Just-in-time access for engineering. Production logs into Datadog with 90-day retention. Every action is auditable.

  • Disclosure.

    Responsible disclosure: security@nimblecross.com. We respond within 24h.