Skip to content
bynh

New — Responsible disclosure programs

Make your compliance visible to everyone.

Certificates, policies, legal terms and your disclosure program in one place, every item documented and verifiable. Customers, partners and regulators see the truth for themselves.

Dokan — Trust Center

Verified · updated 2h ago

SOC 2 Type II
Attested
Valid to Jun 2027
ISO/IEC 27001
Certified
BSI · Cert 741209
GDPR · DPA
Compliant
EU data residency
Disclosure
Open
Safe harbor · paid

SOC 2 Type II report — 2026 · 84 pages

Request access · NDA

Companies that chose transparency with bynh

  • Dokan
  • RMZ
  • Creators
  • USR
  • Sola
  • Lafi

01 — The platform

Every badge has proof behind it.

Every badge on a bynh trust center links to a real document: an auditor’s report, a signed policy, a security measure in place. Anyone can verify it themselves, without having to ask you.

02 — One system of record

“Are you compliant?”Now has one answer.

Compliance, legal and security work from one source. Update a certificate once and it’s current everywhere.

A living registry for SOC 2, ISO 27001, PCI DSS, HIPAA, Cyber Essentials and more. Expiry tracking, auditor details and verification links are built in.

  • Renewal alerts 90 / 30 / 7 days out
  • Public badge, private report, NDA-gated
  • Auditor-signed verification URL

A public page for your security and compliance posture, on your own domain. Badges, documents and answers in one place, with private files behind an NDA.

  • Your domain, your brand
  • Public and NDA-gated sections
  • See who viewed and downloaded

Put a security measure in place once and map it to every framework it satisfies. See what each framework still needs before your auditor does.

  • One measure, many frameworks
  • Gaps listed per framework
  • Evidence collected automatically

Policies, terms and your DPA, versioned, approved and published. Staff acknowledgements are tracked, and every change keeps its history.

  • Counsel-reviewed templates
  • Approvals and acknowledgements tracked
  • Full version history

Run a disclosure program with clear scope, rewards and safe-harbor terms. Reports land in one inbox, and every fix becomes audit evidence.

  • security.txt and a public policy page
  • Private inbox with triage deadlines
  • Fixes mapped to ISO and SOC 2

Customers request private documents in one click. Approve, sign the NDA online and share, with every access logged and set to expire.

  • Click-through or signed NDAs
  • Auto-approve trusted domains
  • Access expires on schedule
Certificate registry7 active
  • SOC 2 Type II2027-06-30Valid
  • ISO/IEC 27001:20222026-10-20Renew 21d
  • PCI DSS v4.0 AOC2027-03-11Valid
  • Cyber Essentials Plus2027-01-04Valid
  • HIPAA attestation—In audit

03 — Disclosure programs

Invite researchers in.On your terms.

Write scope, rewards and safe-harbor terms from counsel-reviewed templates. Publish to your trust center, triage reports, and every fix counts as audit evidence.

  • Step 01

    Define scope

    Assets, severity caps and out-of-scope rules, versioned like code.

  • Step 02

    Set terms & rewards

    Safe harbor, legal terms and reward tiers, signed by counsel.

  • Step 03

    Publish & triage

    security.txt, a public policy page and a private report inbox.

  • Step 04

    Close as evidence

    Each fix maps to ISO A.5.7 and SOC 2 CC7.1 automatically.

Inbox · 5 open

  • #218 IDOR in billing APIHigh
    r.okafor · 2h ago
  • #217 Open redirect on /loginLow
    m.lindqvist · 1d ago
  • #215 Missing SPF on mail.Info
    anon · 3d ago

IDOR in billing API

api.dokan.sa · CVSS 7.1 · in scope

Safe harbor
Terms v3 accepted
SLA
Triage in 22h 14m
Maps to
ISO A.5.7 · SOC 2 CC7.1

Changing the invoice_id parameter on GET /v2/invoices/{id} returns invoices belonging to other tenants. Reproduced with two test accounts; no customer data was accessed beyond the proof of concept.

04 — Status page

Your uptime, out in the open.

Every service checked every 30 seconds. Every outage on the record, with the write-up. The number your customers see is the real one.

99.98%

All systems operational

Dokan · all services · last 90 days

Sep 16 · 99.03%API returned errors for 14 minutesRead the write-up

05 — Coverage

Your framework?It’s covered.

Put a measure in place once and it covers more than one framework. Evidence you collect for one counts toward the rest automatically.

Attestations & certifications

  • SOC 2 Type I & II
  • ISO/IEC 27001 · 27701 · 42001
  • PCI DSS v4.0
  • Cyber Essentials Plus
  • CSA STAR

Regulations & privacy

  • GDPR & UK GDPR
  • HIPAA
  • DORA
  • NIS2
  • NCA ECC · SAMA CSF

06 — For engineers

Up and running on day one.

  • REST + GraphQL APIRead and write every trust object
  • Embeddable badgesLive status that expires with the certificate
  • 60+ evidence integrationsAWS, GCP, GitHub, Okta, Jira, Slack
  • Custom domain + SSOtrust.yourcompany.com in minutes
Publish a certificatecURL
curl https://api.bynh.io/v1/certificates \
  -H "Authorization: Bearer $BYNH_KEY" \
  -d framework="iso27001" \
  -d auditor="BSI Group" \
  -d valid_until="2027-10-20" \
  -d visibility="nda" \
  -F report=@iso27001-2026.pdf

{
  "id": "cert_8f2c41",
  "status": "verified",
  "badge_url": "trust.dokan.sa/b/iso27001"
}

Everything you need to get started.

From zero to a published trust center, this week.

Don’t explain transparency.Prove it.

Your trust center, certificates and disclosure program, live in a day. Free to start.