Security & Compliance

Last updated February 2026

Northlane Data handles account balances and identity documents, so security is part of the product rather than an afterthought. These are the controls in place today.

Encrypted transport and storage

All traffic is served over TLS. Identity documents are written to a private storage bucket that is not publicly readable.

Row-level access control

Every account record is protected by database-level policies, so members can only read and change their own data.

Identity verification

Payouts require a verified identity, which protects balances from account takeover and meets our AML obligations.

Reviewed money movement

Deposits and withdrawals are queued for the operations desk. No automated transfer leaves the platform unreviewed.

Account protection

Sessions are issued per device and can be signed out from account settings. Passwords are never stored in readable form. We recommend a unique password and keeping your email account secured.

Client data handling

Records in review batches are anonymised before they reach an operator. Operators see only the fields needed to answer the review question, and batch content may not be copied, exported or shared outside the platform.

Reporting a vulnerability

If you believe you have found a security issue, contact us through the contact form with the subject "Security report" and a description of the issue and steps to reproduce. Please do not disclose it publicly until we have responded.