Trust center
Security posture
Collections platforms handle sensitive financial and personal data. This page summarises the controls RecoverCollect applies today. It is an operational statement, not a certification claim.
We never store card numbers
Card and bank details are entered in Stripe-hosted fields and tokenised in the browser. RecoverCollect retains only amounts, processor references, and limited metadata needed for receipts and remittances.
Access control by role
Staff access is split across Administrator, Manager, Compliance, and Collector roles. Sensitive actions such as user administration, fee settings, and hard-stop changes require elevated permissions.
Encryption in transit and at rest
All public traffic is served over HTTPS. Application secrets live in server environment variables, not in the client bundle. Database credentials and payment keys never ship to the browser.
Immutable compliance archive
Letters, hard-stop records, and account snapshots are written to an append-only archive on secured server storage with a default seven-year retention window for audits and examinations.
Minimal identity data
Debtors verify with account number, last name, and ZIP code. We do not collect, request, or store Social Security numbers or dates of birth.
Audit logging
Sign-ins, payment applications, letter generation, dispute outcomes, and administrative changes are written to an internal audit log with actor, time, and entity references.
What we are building toward
Formal third-party attestations (for example SOC 2 Type II) and independent penetration tests are roadmap items for production deployments that process live consumer payments at scale. Until those reports are available, treat this page as the current control description rather than a completed audit.
Questions about subprocessors, retention, or a security questionnaire: contact us or review our privacy policy.
Request a security packet