Security Built for the Financial Services Industry
Every layer of our platform is designed with bank-grade security, regulatory compliance, and data protection as core requirements — not afterthoughts.
Bank-Grade Security Built for Financial Services
Our platform adheres to stringent security standards and regulatory requirements, ensuring your financial data and payment operations are always protected.
PSD2 Compliant
Full compliance with EU Payment Services Directive 2
ISO 27001
Information security management system certified
SOC 2 Type II
Service organization controls for security & availability
GDPR Ready
Full EU General Data Protection Regulation compliance
eIDAS Compliant
Electronic identification and trust services regulation
FAPI Security
Financial-grade API security profile implemented
Defence in Depth Security Model
Multiple overlapping security layers protect every API call and byte of data.
Transport Security
- TLS 1.3 encryption for all connections
- Mutual TLS (mTLS) for API clients
- Certificate pinning for mobile SDKs
- HSTS headers enforced
Authentication & Authorisation
- OAuth 2.0 with PKCE
- OpenID Connect for identity
- FAPI 1.0 Advanced security profile
- JWT with short expiry & rotation
Data Protection
- AES-256 encryption at rest
- Field-level encryption for PII
- Data minimisation principles
- Right to erasure (GDPR Article 17)
Operational Security
- 24/7 Security Operations Centre
- Automated threat detection & response
- Penetration testing quarterly
- Bug bounty program
Regulatory Compliance
Full compliance with European and international financial regulations
| Standard / Regulation | Authority | Scope | Status |
|---|---|---|---|
| PSD2 – Payment Services Directive 2 | European Banking Authority (EBA) | Open banking APIs, SCA, TPP access | Compliant |
| GDPR – General Data Protection Regulation | EU Data Protection Boards | Personal data processing & privacy | Compliant |
| ISO/IEC 27001:2022 | BSI / Third-party auditor | Information security management | Certified |
| SOC 2 Type II | AICPA Third-party auditor | Security, availability & confidentiality | Certified |
| eIDAS – Electronic Identification | EU Member State supervisors | Digital identity & trust services | Compliant |
| FAPI – Financial-grade API | OpenID Foundation | High-security API profile | Implemented |
Build on a Compliant Foundation
Our platform handles PSD2 compliance so your team can focus on building great products.