Security with
real stakes.

People put their money, career applications and private knowledge into our products. At SPINZ, security engineering protects the decisions that follow: who controls an account, whether access remains valid, and what private information a system keeps.

Accountable at the top.

Elias Vouteris

CEO · Security lead

Elias Vouteris, CEO, is responsible for information security at SPINZ.

Security engineering.

Our internal product development function performs security reviews, investigates vulnerabilities and carries remediation through to code and verification. The work covers our own software and the infrastructure behind it.

Nikiforos Vouteris
Co-writer of these engineering notes and credited with discovering the findings they describe.

Our responsibility.

CairnPay, Earlydesk and ControlRoom are company-owned products. Our internal security remit includes their applications and infrastructure.

Testing of third-party systems requires explicit authorization from their owner.

Enforce the decision.

A sensitive action needs proof the server can check. Access changes need to hold during concurrent work. Private information needs a clear reason to remain in a record. Our engineering work addresses those boundaries directly.

RequestSensitive account change
BoundaryFresh identity proof
OutcomeServer decides

CairnPay checks the current password and, when two-factor authentication is enabled, a fresh authenticator code before changing the password.

Defensive engineering.

The decisions behind stronger account protection, enforceable revocation and a smaller footprint for private data.

CairnPay

Protecting who controls the account.

A credential change can decide who keeps control of an account. We require fresh proof at that decision.

CairnPay

Revocation must hold under pressure.

Checkout creation, key revocation and merchant suspension need an order the payment system can enforce.

Earlydesk

Private answers deserve a smaller footprint.

Reducing the sensitive information left behind by application workflows, including their change-tracking records.

Report a security concern.

Tell us which product or system is involved, what you observed and how to reproduce it safely. Synthetic examples help us investigate without exposing private records or credentials.