Security
Security is one of the biggest considerations in everything we do. If you have any questions, or encounter any issues, please contact us at [email protected].
PCI
White is certified to PCI Service Provider Level 2.
SSL
White forces HTTPS for all services, including our public website. We regularly audit the details of our implementation: the certificates we serve, the certificate authorities we use, and the ciphers we support.
Encryption
All card numbers are encrypted on disk with AES-256. Decryption keys are stored on separate machines. None of White’s internal servers and daemons are able to obtain plaintext card numbers; instead, they can just request that cards be sent to a service provider on a static whitelist. White’s infrastructure for storing, decrypting, and transmitting card numbers runs in separate hosting infrastructure, and doesn’t share any credentials with White’s primary services (API, website, etc.).
Disclosure
We rapidly investigate all reported security issues. If you believe you’ve discovered a bug in White’s security, please get in touch at [email protected] (optionally using our PGP key at the bottom of this page). We will respond as quickly as possible to your report. We request that you not publicly disclose the issue until it has been addressed by White.
Thank you for helping keep White, our users, and their customers safe!
PGP
Our PGP key is below. You can use this key to encrypt your communications with White, or verify signed messages you receive from White. (Unfamiliar with PGP? Have a look at GPG, and start by importing a public key.)
- Key ID: 0DF9E7F6
- Key type: RSA
- Key size: 2048
- Fingerprint: B9CD EE6D 0D82 AFEC 1B7F 1511 926A D7AF 0DF9 E7F6
- User ID: [email protected]
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 | -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v1 mQENBFOqnA8BCADOomqawEsl2ppI8plBa/l4VfbmZjlEdhunjFpY+JRxY25wUQnK 65GODaneCHLfOon9k56r9R0AUpJKC58KlJC3BbS8RQRDEwY3ga6xHMloRn74T7Ju 1F/sk7Azq+B93rbXXod21m7QFSkqan1z+GUJnY/NvOezB+1z8AULiWbKejWjPAHv +3N0FULRwWmybLmXmMTHhj2YFgjo4r+dn6MNFtk2/HmEnjG9khFbXJCHT1GI/sTM OFj9EOJASxVNPx17Xe/IMjkxSRbGJ2RSxjcAyI2pbdBE9OGuKgDqoL2OYerGn5Gj e0KW0mBH9rF/xqLqZ4+6lEhpl4gmGIias8KlABEBAAG0H1lhemluIDx5YXppbkB3 aGl0ZXBheW1lbnRzLmNvbT6JAT4EEwECACgFAlOqnA8CGyMFCQlmAYAGCwkIBwMC BhUIAgkKCwQWAgMBAh4BAheAAAoJEJJq168N+ef2ldIIAJph+kDQMYCP9JYW+quO nlBJz44lVrVDQ61zBiJeyktecRJ7p1pjUPVbBrLmyN6yAw0BHPzLgYGg2FaXTtcH bJfqkvgjLoPqRcYNjnQ3EGkGsuOg+DVY/Oj1V9U9Zac0De1hhmuOVHcl1laO6NUZ 0uYwm/NvbLABi00Qt0kNjkvB79Wi2KAuRV2owgpWmSorWtpkxfH03eofU0/k86t6 nLBDWpT/SAYVZfSIZh3LYBQcYKUIFWklPF8VaXYfQKqlqTqKkOVk1K1equGmz+KA ShSjPLHMXCLgWACYkNOhcSeOSXsIOruzCRSQz2a34PEFRG2baXTI1U6FZJ90n3rZ r3u5AQ0EU6qcDwEIALK+c8Oj9i8PLSWhxQTJneEsekUlQ8ID9Gc526UMiA4K3Zgk /Vwc2J/u2ZoVsjIxvn33fWfvazu+fcJFPtaAK2UKfG2+Q1aItaf2M0EWLBnpw5qe pLvQIieIyN5jCUI4M/5NJiL8Mo0Py2+j8yeQTa4lzl6vI1qCxBt8VYOfLrHJy4q6 KAxOnz19nt4uyHKY0t8A/+9zj9PcTi/vSyjDnFEn6zLD/866KnK/QPqyYd5Kkqd2 1gKrsmZiiU8/KLdJDjPiiqwTNN7pZpStPhkj375oYdTIAfQ9vu7InViISyuDAqAU qjIoIElyoW6i5T9Kpj0+rWC0uo1lIDRzSpa03okAEQEAAYkBJQQYAQIADwUCU6qc DwIbDAUJCWYBgAAKCRCSatevDfnn9uuBCACDXcuGOI83fRBzp0sMUmS3dufWKCvR 2mnKKHlEbatB5Vrnr9ZQndOPBv1o30/ephuvOgo8V+tV9aNKjXyoQ/Q/1fPVcZmU xZpJFeKRgoqlvolkJLYHjpDi4eaN2gs7s8dZb37oDpsDqXy92E5OEHcpdFlG77/I pEkAd9Dkb6deZze/9YcgAUITYD1DJ2gsoX+OotTLW+9+b4xyEOyUJozEIX5dvK/n mwCDZOdsn+g1HVu/W9Rp2DqJBxlXylIzGr3FRheJt/siBTz4k8dVWCw4H2P78St7 yw5PM1Bp/t19KwDPDC7G322D+cQgSzlksWZM/iO+6yDnLsjSifrmsKVN =nJaQ -----END PGP PUBLIC KEY BLOCK----- |