Built and operated for regulated money
Single-tenant isolation, encryption everywhere, continuous monitoring, and a 24/7 incident response you can hold to an SLA.
Formance runs financial systems of record for regulated companies, and the security program is built to survive their reviews: independent audits with clean opinions, annual external penetration testing, cloud-native detection, and a documented, tested incident response. Reports and attestations live at trust.formance.com; a responsible disclosure policy is published at formance.com/security.
Architecture
Each cloud customer runs in a dedicated private region in a separate AWS account. Nothing multi-tenant, nothing shared.
VPC peering to your infrastructure; standard deployments expose nothing to the public internet.
AES-256 at rest, TLS 1.2+ in transit with HSTS, keys in AWS KMS with rotation and logged access, per NIST SP 800-57.
Access
OIDC SSO, MFA on all privileged access, zero-privilege-by-default roles, quarterly access reviews, revocation within 24 business hours of departure.
Immutable, hash-chained audit logs on every platform and service action, with actor and timestamp.
Detection & response
AWS GuardDuty, Security Hub, Inspector, and CloudTrail across all production accounts; compliance monitored continuously in Vanta.
24/7 on-call with executive escalation, 30-minute Severity-1 first response, plan tested annually, post-mortems after every security incident.
Annual external penetration testing (never internal), additional tests after major changes, quarterly external vulnerability scans.
Resilience
99.9% SLA on Formance-hosted deployments across 3 availability zones with 6-node replication.
Encrypted backups, restoration tested at least annually, ledger export for independent copies at any time.
No major security breaches or data loss to date; SOC 2 Type II audit passed with zero exceptions across all 33 criteria.
Audited by Johanson Group LLP; clean opinion, no exceptions noted across all 33 criteria tested.
Certified ISMS; 16 formal security policies reviewed annually.
Assessed across Articles 5 to 30 and 45; no material deficiencies identified.
Built for regulated money.
Enterprise controls, the certifications auditors ask for, and an immutable record, out of the box.
09:41:07Z AUDIT gateway POST /api/ledger/v2/main/transactions 200 sub:ops@acme.io
09:41:09Z LOG id:4093 NEW_TRANSACTION ledger:main
09:41:12Z LOG id:4094 SET_METADATA ledger:main
09:41:15Z LOG id:4095 REVERTED_TRANSACTION ledger:main
09:41:18Z AUDIT gateway GET /api/ledger/v2/main/logs 200 sub:audit@acme.io
Keep going
Everything you need to evaluate and build on Formance.
Questions, answered
01 / WHO PERFORMS YOUR PENETRATION TESTS?
Independent external testers, annually and after major changes, with results feeding a documented remediation workflow. Formance also retains an external virtual CISO.
02 / CAN WE FEED YOUR LOGS INTO OUR SIEM?
Yes. Audit logs auto-sync to customer SIEMs, and platform logs and traces export to any OpenTelemetry-compatible backend.
03 / WHERE IS DATA STORED?
In the region you choose, in a dedicated AWS account (cloud) or on your own infrastructure (self-hosted). Backups replicate only within the same jurisdiction.
04 / HOW DO WE RUN OUR SECURITY REVIEW?
Start at trust.formance.com for reports and the sub-processor list, and use InfoSec office hours with the Formance security team for anything deeper.
Bring your security review
Get the reports, then get your questions answered live: book a demo or visit the trust center.