Audited, certified, and continuously monitored
SOC 2 Type II with zero exceptions, ISO 27001:2022, and DORA alignment: the certifications your auditors ask for, backed by evidence you can hand them.
Compliance at Formance is a program, not a page: independent audits on a fixed cadence, 16 formal security policies reviewed annually, continuous control monitoring in Vanta, and contracts already aligned with EU operational-resilience requirements. Everything below is documented and available under NDA through the trust center.
SOC 2 Type II
Audited by Johanson Group LLP; all 33 Common Criteria tested with no exceptions noted.
Control environment, risk assessment, access, operations, change management, and vendor risk (CC1 through CC9).
Re-audited on a rolling annual period, with the current report available under NDA.
ISO 27001:2022
Information security management system certified against the 2022 revision.
16 formal policies (access, cryptography, incident response, BC/DR, secure development, and more) reviewed and renewed annually.
External audit plus annual risk assessments based on ISO 27005 and NIST 800-30.
DORA
Full assessment across Articles 5 to 30 and Article 45, covering governance, resilience testing, incident reporting, and third-party risk.
Contracts aligned with DORA requirements out of the box, and a maintained register of ICT arrangements.
Critical systems tested at least yearly; threat-led penetration testing at least every 3 years by external testers.
Built for regulated money.
Enterprise controls, the certifications auditors ask for, and an immutable record, out of the box.
09:41:07Z AUDIT gateway POST /api/ledger/v2/main/transactions 200 sub:ops@acme.io
09:41:09Z LOG id:4093 NEW_TRANSACTION ledger:main
09:41:12Z LOG id:4094 SET_METADATA ledger:main
09:41:15Z LOG id:4095 REVERTED_TRANSACTION ledger:main
09:41:18Z AUDIT gateway GET /api/ledger/v2/main/logs 200 sub:audit@acme.io
Keep going
Everything you need to evaluate and build on Formance.
Questions, answered
01 / HOW DO WE GET THE REPORTS?
Through the trust center under NDA, or alongside your RFP. The latest audit reports ship with security questionnaire responses as standard.
02 / WE ARE IN SCOPE FOR DORA. WHAT DOES THAT MEAN FOR YOU AS OUR ICT PROVIDER?
Formance maintains DORA-aligned contract terms, a register of ICT arrangements, incident classification aligned with Articles 13 and 14, and a resilience testing program, so your third-party risk file is ready.
03 / WHAT ABOUT GDPR?
Formance processes data under a DPA with GDPR-aligned safeguards, EU hosting options, jurisdiction-bound backups, and a published sub-processor list.
04 / DO YOU SUPPORT CUSTOMER AUDITS?
Yes, audit rights are part of the contractual framework, and continuous monitoring evidence (Vanta) plus annual external audits back the paper.
Evidence, not assurances
Request the reports or bring your compliance team to a session.