Tilmeld dig i dag, og betal ingen gebyrer i 90 dage. Der gælder vilkår og betingelser
Tilmeld dig i dag, og betal ingen gebyrer i 90 dage. Der gælder vilkår og betingelser
Paid with GoCardless? Read our FAQ for customers
Got a question? Raise a ticket with our Support team
We are authorised by the Financial Conduct Authority to provide payment services as an Authorised Payment Institution. We serve more businesses than any other Direct Debit provider. All money collected is held in a secure client monies account with either the Royal Bank of Scotland, Barclays Bank, BNP Paribas, Danske Bank, JP Morgan, RBC, CFSB or ASB.
At GoCardless we know security is important, especially when it comes to payments. Our merchants rely on us to invest in security and maintain robust data protection for them and their customers.
Our access to the Direct Debit system is provided by major banks, who have approved our systems.
GoCardless is a UK-based company subject to some of the strictest data protection rules in the world. We protect your data under a global data protection, privacy and security programme based on the requirements of the EU General Data Protection Regulation, which also meets the standards set by the Australian Privacy Principles. To learn more about our programmes, read the GoCardless Privacy Notice.
Our financial data server is separated from our application server by multiple firewalls.
All client-server communication is 256-bit SSL encrypted. The banking system requires just 128-bit.
We have received ISO 27001 certification for information security.
GoCardless has been awarded ISO 27001 certification. ISO 27001 is a widely recognised, internationally accepted standard for information security and we have attained it across all GoCardless services and products. An accredited independent auditor has assessed our processes and controls, and confirmed they align with the certification standard. British Assessment Bureau , an ISO accredited certification body, has certified our compliance with the ISO standard. Having ISO 27001 certification helps assure our merchants and their customers that we take information security management seriously. GoCardless will ensure that an independent auditor will reassess our Information Security Management System on an annual basis.
All money collected is held in a secure client monies account held with one of our partner banks. Funds are held fully in accordance with safeguarding provisions.
Yes. Your customers are fully protected by the Direct Debit Guarantee. This entitles them to a full and immediate refund of any payments taken from their account in error.
We care deeply about keeping our users safe. If you believe you have discovered a vulnerability, we ask that you disclose it in a responsible manner. Sharing vulnerabilities publicly puts our entire user base at risk, so we urge you to keep issues private until we’ve had a chance to release a fix. If you are interested in testing our service for vulnerabilities, then we would appreciate any reports regarding our Merchant Dashboard and API. Please conduct testing on our Sandbox environment only. You can sign up for a Sandbox account to get started. Our developer documentation provides details on how to configure an account.
Report via https://hackerone.com/gocardless_bbp or email vuln-disc@gocardless.com as soon as you become aware of the issue.
You will be asked to register on HackerOne and submit the issue via our Bug Bounty Program.
In the initial email include a general overview of the issue, please do not include steps for reproducing the issue. We will provide you a secure way to communicate further details.
When demonstrating the issue only exploit the vulnerability using a benign payload to demonstrate the issue using your own accounts.
Do not disclose the issue to anyone else until we have confirmed a fix or resolution.
When reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:
Denial of service attacks
Do not attempt to access or modify any user data that is not your own.
Do not degrade the performance of our services (e.g. via automated scanning, brute forcing, or denial of service attacks)
Social engineering attacks
Physical attacks or threats against our staff or users
Theoretical scenarios that do not demonstrate an impact. E.g. a tool reporting a weak cipher suite due to lack of Perfect Forward Secrecy.
Got a question? Raise a ticket with our Support team