Timbro policies
Security Policy
How we protect checkout, payments, and the information you entrust to us.
Checkout protection
Timbro serves checkout over encrypted connections and limits each session through links and credentials with narrow permissions. The browser never receives provider secrets or administrative credentials.
Operational controls
We protect integration secrets in server services, record statuses without storing unnecessary sensitive data, control access to logs, and monitor errors and abuse signals. Ambiguous operations are verified before we show a final result.
Business certificates
If you provide a P12 file and its password through a secure channel authorized by Timbro, we treat them as confidential security credentials, restrict access, and use them for authorized signing operations. Never send them by email, chat, or contact forms.
Additional verification
Depending on the bank, card, business, and amount, payment may ask for additional confirmation. Do not close or repeat the payment while it is in progress.
Report a problem
Report phishing, misuse, or vulnerabilities to hola@timbro.do. Include a reproducible description, never passwords, tokens, certificates, or full card details.