Security & procurement

Evidence for teams buying synthetic payment QA.

A concise view of the boundaries, controls and artifacts you can review before connecting IBANgen to a payment, onboarding or QA workflow. The page describes current controls without inventing certifications, uptime guarantees or live-account verification.

Synthetic-only boundary

Generated IBANs, profiles and provider fixtures are for QA, staging and conformance work. They are not real accounts, do not prove ownership and do not execute payments.

Document handling

Statement review follows the short-retention contract in the Privacy Policy. Uploads are not used to train models; closed reviews can be deleted through the documented workflow.

Registry provenance

Bank and identifier metadata carries source, snapshot and coverage context. Runtime registry files are checksum-verified and kept outside the deploy checkout.

Controlled operations

API keys, plan entitlements, bounded jobs, idempotency keys, worker health and guarded deployments are part of the operating path. Paid production releases require protected configuration.

Procurement boundary

What a review can include

Send the intended countries, target banks/BICs, API volume, document types and retention requirements. The team can then scope the data boundary and provide the relevant evidence before an agreement is accepted.

Claims we deliberately do not make

IBANgen does not claim live bank-account verification, a public uptime SLA, 24/7 support, a security certification or enterprise procurement readiness before the relevant evidence and legal operator configuration are in place.

Frequently reviewed questions

Does IBANgen verify live bank accounts?

No. IBANgen creates synthetic QA data and reports format, checksum, metadata, or visible document signals. It does not perform live account ownership verification.

How are uploaded bank statements handled?

Statement uploads follow the documented short-retention contract, are not used to train models, and can be deleted through the review workflow when the case is closed.

Can procurement teams request security evidence?

Yes. Send the intended data boundary, API scope, countries, and retention requirements through the Business intake before any paid procurement agreement is accepted.