BlackOak

Security posture

Built so the blast radius is small by design.

BlackOak is being built as a financial technology company working with regulated partners. These are the design decisions that determine what can go wrong, how far it can reach, and who can see what.

Request early access
01

The strongest control is the data you never take.

Most security posture is a list of controls bolted onto a system that collects everything. The decisions below were taken the other way round — narrowing what BlackOak holds, who can reach it, and what a participant can see about anyone else, before the controls were designed at all.

01

Card data stays out of the merchant's scope

Hosted checkout is the documented default, with a direct card API available only to merchants who already carry the wider PCI obligation. A merchant who takes the default never handles a card number, so their compliance scope stays as small as the design allows.

02

Possession first, then a real second factor

Signup verifies phone possession, where carrier tenure, porting and SIM-swap history are readable before a code is sent. Ongoing access is being designed for passkeys and authenticator apps rather than SMS, which is the right signal at signup and the wrong one for standing access.

03

Program partners see participation, not people

Where BlackOak runs a program for an institution, that institution is designed to receive aggregate participation and outcome reporting. Individual account and transaction activity is not theirs to see, and the separation is structural rather than a reporting preference.

04

Owners verify themselves, separately

Each beneficial owner completes their own section under their own one-time code on their own number, with sectioned visibility. Nobody assembles a file on their co-owners in order to open an account.

What is settled, and what is not

Record retention
Seven years
Card data handling
Hosted by default; direct API by exception
Standing authentication
Passkey and authenticator, in design
Institutional reporting
Aggregate only, by construction
Formal attestation
Follows launch, with the bank partner

Two halves of
one program.

Security and compliance are the same program viewed from two directions. What BlackOak collects is a compliance obligation; what it does with it afterwards is a security one.

Diligence · Partners · Program sponsors

Ask the harder questions.

If you are assessing BlackOak as a bank, network, processor, or program sponsor, the useful conversation is the specific one. Start it and we will bring the detail this page deliberately does not publish.

Start a diligence conversation