Security at Credicorp
We take the security of our systems and customer data seriously. This page sets out our security posture, responsible-disclosure process, and how to contact us if you discover a vulnerability.
Security
Report a vulnerability
Found a security issue in a Credicorp system? Use our coordinated-disclosure form. We aim to respond within five business days.
Submit a report →Security contact
For urgent security matters, email us directly. Please do not share vulnerability details publicly before we have had a chance to investigate.
security@credicorp.co.ukOur security practices
- Data encryption: all data in transit is encrypted with TLS 1.2+. Sensitive data at rest is encrypted at the storage layer.
- Access control: production access is restricted to named personnel, MFA-enforced, and audited. We follow the principle of least privilege.
- Open Banking: Credicorp uses FCA-regulated Open Banking connections only. We never ask for your online banking password.
- Third parties: all third-party integrations are reviewed for security and data-handling practices before onboarding.
- Monitoring: our systems are monitored 24/7 for anomalous behaviour. Security events are logged and reviewed.
Responsible disclosure policy
We ask that researchers follow coordinated disclosure: report findings to us privately and give us a reasonable period to investigate and address the issue before public disclosure. We will not take legal action against researchers who act in good faith.
In scope: credicorp.co.uk, clients.credicorp.co.uk, hub.credicorp.co.uk, and any other Credicorp-operated systems. Out of scope: third-party services, denial-of-service testing, or social engineering against Credicorp personnel.
Found something?
Use our vulnerability-disclosure form to report it privately. Include steps to reproduce, the potential impact, and any supporting evidence. We appreciate researchers who take the time to help keep our systems safe.
Submit a report
®