Blackwall Systems
Return home

Security & Data Protection

How Blackwall protects data

Effective date: August 25, 2026

This policy summarizes the security and data-protection controls Blackwall Systems applies to its services and the personal data processed through them.

1. Security principles

  • Data minimization: process only information necessary for an enabled function or legitimate business purpose.
  • Least privilege: limit administrative and customer-data access to authorized personnel who require it.
  • Defense in depth: combine platform security, authentication, encryption, application controls, logging, and monitoring.
  • Purpose limitation: do not repurpose merchant customer information for unrelated advertising or sale.

2. Authentication and staff access

Administrative accounts must use unique, strong passwords. Multi-factor authentication is required where supported for systems that can access production infrastructure, source code, customer data, billing systems, or security administration. Shared credentials are prohibited except for specifically controlled service credentials.

Access is granted according to role and operational need and should be removed or reduced when no longer necessary.

3. Encryption and secrets

Blackwall uses HTTPS/TLS for data in transit. Production databases and platform storage use hosting-provider protections for data at rest. Application credentials and merchant-supplied provider secrets are encrypted before persistent storage where Blackwall stores them. Secrets must not be committed to public source repositories or exposed in client-side application code.

4. Environment separation

Development and testing must be logically separated from production. Production customer personal data must not be copied into development or test environments except where specifically authorized, necessary, minimized, and protected. Development stores and synthetic/test records should be used for routine testing.

5. Logging and monitoring

Blackwall maintains operational and security logging appropriate to sensitive administrative functions, authentication, privacy operations, and system errors. Logs should avoid storing plaintext secrets and should minimize unnecessary personal data. Access to sensitive logs is restricted.

6. Data-loss prevention

Blackwall's data-loss-prevention strategy includes least-privilege access, encrypted transport, controlled exports, secret-management practices, restricted production access, logging, privacy deletion workflows, source-control exclusions for secrets, and a prohibition on copying production customer data into uncontrolled systems.

7. Backups and resilience

Where Blackwall or its infrastructure providers maintain backups, replicas, snapshots, or recovery copies containing protected data, those copies must receive access controls and encryption protections appropriate to the production data they contain. Blackwall relies in part on managed infrastructure providers for platform-level durability and recovery capabilities.

8. Vulnerability and change management

Blackwall reviews dependency, platform, and application changes for security impact; updates supported components as appropriate; tests material changes before production use; and prioritizes remediation of vulnerabilities according to severity and exploitability.

9. Third-party services

Third-party providers are selected based on functional need and appropriate security/privacy capabilities. Blackwall limits data shared with providers to what is needed for the configured service.

10. Incident response

Suspected security incidents are handled under the Incident Response Policy, including triage, containment, investigation, remediation, recovery, and required notifications.

11. Security contact

Security concerns may be reported through the Blackwall Systems contact form. Do not include passwords, full payment-card numbers, or other unnecessary secrets in an initial report.

Terms of Service Privacy Policy Data Processing Addendum Security & Data Protection Data Retention Incident Response Refund & Cancellation Trust Center Contact
© 2026 Blackwall Systems. All rights reserved. Trust Center