Security & compliance
Institutional-grade security. Consumer-grade simplicity.
Every part of Bright Future is engineered around one principle: your money and your data are yours alone. Here is how we keep them that way.
Biometric login
Face ID and Touch ID authenticate every session on trusted devices.
Two-factor authentication
One-time codes over authenticator apps, hardware keys and secure push.
AES-256 encryption
Data encrypted at rest and TLS 1.3 in transit — end-to-end, no exceptions.
SCA on every payment
Strong Customer Authentication for every transfer, no matter the value.
Isolated infrastructure
Multi-region resilience, hardened Kubernetes, secrets-manager-only credentials.
24/7 fraud monitoring
ML-based anomaly detection, human analysts and instant in-app alerts.
Regulatory status
Regulated where we operate.
Bright Future is an electronic money institution operating under regulatory permissions in the United Kingdom, the European Union, the United Arab Emirates and Singapore. Customer funds are safeguarded with tier-1 credit institutions in each jurisdiction.
- United Kingdom — Financial Conduct Authority (EMI, reference on request)
- European Union — De Nederlandsche Bank (EMI passported into the EEA)
- United Arab Emirates — Central Bank of the UAE (registered agent)
- Singapore — Monetary Authority of Singapore (major payment institution)
- SOC 2 Type II report available under NDA
- PCI-DSS v4.0 compliant for card issuing and processing
Responsible disclosure
Found something? Tell our team first.
We operate a coordinated disclosure programme. Security researchers can report vulnerabilities to security@brightfuture.bank. We acknowledge every report within 24 hours and publish public bounties for in-scope findings.
