Information Security Policy
Last updated: May 4, 2026
planB is designed so that the user has direct control over their own funds and data. The principles and practices below describe how we protect that control.
Self-custody of cryptographic keys
Your private keys (Bitcoin and EVM) never touch our servers. Custody is handled by your own device, with encrypted shards managed by the authentication infrastructure of our partner Privy Inc., under your exclusive control. planB cannot move your funds.
Visa card: issuer-side tokenization
The Visa card is issued by Gnosis Pay Ltd. (gnosispay.com) in partnership with UAB Monavate (monavate.com - Lithuania, regulated by the Bank of Lithuania) as BIN sponsor. Sensitive card data (number and CVV) is tokenized by the issuer's SDK and never transits planB's infrastructure in plaintext.
Pix: rails regulated by the Brazilian Central Bank
Pix operations are processed by Avenia, a Brazilian payments provider that operates within the Brazilian Central Bank regulatory framework via authorized banking partners. KYC is mandatory before any Pix movement; the app blocks operations until KYC is approved by the regulated operator.
Encryption in transit and at rest
All traffic between the app and our infrastructure is protected by TLS with certificate pinning. Databases on our infrastructure are encrypted at rest. Operations on public networks (blockchains) follow the cryptographic standards of the networks themselves.
Protocol-level compliance on exchange routers
The decentralized exchange routing protocols used internally for currency conversion apply real-time screening against sanctions lists via first-tier blockchain intelligence providers. Operations involving sanctioned addresses are automatically blocked at the protocol level.
Identity verification (KYC)
Identity verification at onboarding is performed by Sumsub, which captures and validates identity documents and biometrics, and runs sanctions and PEP screening before any regulated operation is allowed. Sumsub is visible to the user during the KYC flow.
Regulatory screening at KYC operators
Avenia (Pix) and Gnosis Pay Ltd. together with UAB Monavate (Visa card) also perform full KYC, AML, sanctions, PEP and OFAC screening under their respective regulatory frameworks.
Monitoring and incident response
Errors and anomalies are detected in real time by monitoring providers configured not to capture personal data. Security incidents are handled by our internal team per our incident response policy. Material personal-data incidents will be notified to the ANPD and to affected customers within the timeframes required by LGPD.
Cloud infrastructure
The back-end infrastructure runs on cloud providers offering network isolation, access control and regular backups. The categories of providers and the type of data shared with each category are described in the Privacy Policy.
Vulnerability reporting
Found a vulnerability? Write to contact@planb.army. We ask that you report responsibly (without public disclosure before a fix is in place).
Contact
Security concerns, suspected vulnerabilities and data-protection requests can be sent to:
📧 contact@planb.army (with subject line "Security" — these are routed to our security lead)