Security & Compliance
Last updated February 2026
Northlane Data handles account balances and identity documents, so security is part of the product rather than an afterthought. These are the controls in place today.
Encrypted transport and storage
All traffic is served over TLS. Identity documents are written to a private storage bucket that is not publicly readable.
Row-level access control
Every account record is protected by database-level policies, so members can only read and change their own data.
Identity verification
Payouts require a verified identity, which protects balances from account takeover and meets our AML obligations.
Reviewed money movement
Deposits and withdrawals are queued for the operations desk. No automated transfer leaves the platform unreviewed.
Account protection
Sessions are issued per device and can be signed out from account settings. Passwords are never stored in readable form. We recommend a unique password and keeping your email account secured.
Client data handling
Records in review batches are anonymised before they reach an operator. Operators see only the fields needed to answer the review question, and batch content may not be copied, exported or shared outside the platform.
Reporting a vulnerability
If you believe you have found a security issue, contact us through the contact form with the subject "Security report" and a description of the issue and steps to reproduce. Please do not disclose it publicly until we have responded.