Security with
real stakes.
People put their money, career applications and private knowledge into our products. At SPINZ, security engineering protects the decisions that follow: who controls an account, whether access remains valid, and what private information a system keeps.
Accountable at the top.
Elias Vouteris
CEO · Security lead
Elias Vouteris, CEO, is responsible for information security at SPINZ.
Security engineering.
Our internal product development function performs security reviews, investigates vulnerabilities and carries remediation through to code and verification. The work covers our own software and the infrastructure behind it.
Nikiforos Vouteris
Co-writer of these engineering notes and credited with discovering the findings they describe.
Our responsibility.
CairnPay, Earlydesk and ControlRoom are company-owned products. Our internal security remit includes their applications and infrastructure.
Testing of third-party systems requires explicit authorization from their owner.
Enforce the decision.
A sensitive action needs proof the server can check. Access changes need to hold during concurrent work. Private information needs a clear reason to remain in a record. Our engineering work addresses those boundaries directly.
CairnPay checks the current password and, when two-factor authentication is enabled, a fresh authenticator code before changing the password.
Defensive engineering.
The decisions behind stronger account protection, enforceable revocation and a smaller footprint for private data.
Protecting who controls the account.
A credential change can decide who keeps control of an account. We require fresh proof at that decision.
CairnPayRevocation must hold under pressure.
Checkout creation, key revocation and merchant suspension need an order the payment system can enforce.
EarlydeskPrivate answers deserve a smaller footprint.
Reducing the sensitive information left behind by application workflows, including their change-tracking records.
Report a security concern.
Tell us which product or system is involved, what you observed and how to reproduce it safely. Synthetic examples help us investigate without exposing private records or credentials.
For ControlRoom, contact the owner of your private workspace. If you are unsure which SPINZ service is affected, use CairnPay’s contact page and identify the product or infrastructure involved.
Use synthetic examples wherever possible. Do not include passwords, API keys, payment credentials or other people’s personal records. Keep testing within systems you own or have explicit permission to assess.