Skip to content
PegoraProductsPricing

Security

Last updated: 16 August 2026

Encryption

Everything between your browser and Pegora travels over encrypted connections (TLS). The most sensitive identifiers you give us — PPS and National Insurance numbers — are additionally encrypted in the database itself (AES-256-GCM), so even someone with the database in hand can't read them. They are never sent back to your browser in full; you only ever see a masked version.

No passwords, no card numbers

Sign-in is by emailed link, so there is no password database to steal. When paid plans launch, card details will be handled entirely by a dedicated payment provider — Pegora will never see or store them.

Least privilege by construction

The credentials our systems run with can each do exactly one job — the key that sends sign-in emails, for example, can send from one address and nothing else. Every metered or sensitive action is rate-limited, and the AI features have hard daily spending ceilings per account.

Certifications — honestly

We do not yet hold SOC 2 or ISO 27001 certification. Those are audited standards that come with scale, and we would rather tell you exactly what we do than wear a badge we haven't earned. This page is kept current so you can judge our practices directly.

Found a vulnerability?

Tell us. Security reports are treated as our highest-priority bugs — we will acknowledge quickly, fix quickly, and credit you if you'd like. Contact us at the address on our site.