Skip to content
_SECURITY/

Built and operated for regulated money

Single-tenant isolation, encryption everywhere, continuous monitoring, and a 24/7 incident response you can hold to an SLA.

Formance runs financial systems of record for regulated companies, and the security program is built to survive their reviews: independent audits with clean opinions, annual external penetration testing, cloud-native detection, and a documented, tested incident response. Reports and attestations live at trust.formance.com; a responsible disclosure policy is published at formance.com/security.

_01/

Architecture

_Single-tenant isolation/

Each cloud customer runs in a dedicated private region in a separate AWS account. Nothing multi-tenant, nothing shared.

_Private networking/

VPC peering to your infrastructure; standard deployments expose nothing to the public internet.

_Encryption/

AES-256 at rest, TLS 1.2+ in transit with HSTS, keys in AWS KMS with rotation and logged access, per NIST SP 800-57.

_02/

Access

_SSO, MFA, RBAC/

OIDC SSO, MFA on all privileged access, zero-privilege-by-default roles, quarterly access reviews, revocation within 24 business hours of departure.

_Non-repudiation/

Immutable, hash-chained audit logs on every platform and service action, with actor and timestamp.

_03/

Detection & response

_Continuous monitoring/

AWS GuardDuty, Security Hub, Inspector, and CloudTrail across all production accounts; compliance monitored continuously in Vanta.

_Incident response/

24/7 on-call with executive escalation, 30-minute Severity-1 first response, plan tested annually, post-mortems after every security incident.

_Testing/

Annual external penetration testing (never internal), additional tests after major changes, quarterly external vulnerability scans.

_04/

Resilience

_Availability/

99.9% SLA on Formance-hosted deployments across 3 availability zones with 6-node replication.

_Backups/

Encrypted backups, restoration tested at least annually, ledger export for independent copies at any time.

_Track record/

No major security breaches or data loss to date; SOC 2 Type II audit passed with zero exceptions across all 33 criteria.

_SHOWCASE/
SOC 2 Type II

Audited by Johanson Group LLP; clean opinion, no exceptions noted across all 33 criteria tested.

ISO 27001:2022

Certified ISMS; 16 formal security policies reviewed annually.

DORA

Assessed across Articles 5 to 30 and 45; no material deficiencies identified.

_TRUST/

Built for regulated money.

Enterprise controls, the certifications auditors ask for, and an immutable record, out of the box.

See our trust center
THE COMPLIANCE STACK
IAM, RBAC & SSO
Non-repudiation
Audit logs
Observability & monitoring
Real-time events
Admin console
_AUDIT-LOG/ NON-REPUDIATION

09:41:07Z AUDIT gateway POST /api/ledger/v2/main/transactions 200 sub:ops@acme.io

09:41:09Z LOG id:4093 NEW_TRANSACTION ledger:main

09:41:12Z LOG id:4094 SET_METADATA ledger:main

09:41:15Z LOG id:4095 REVERTED_TRANSACTION ledger:main

09:41:18Z AUDIT gateway GET /api/ledger/v2/main/logs 200 sub:audit@acme.io

CERTIFICATIONS
AICPA SOC IICERTIFIED
ISO 27001CERTIFIED
DORACOMPLIANT
REGULATORY FRAMEWORKS
EMIFCAMTLNYDFS Trust CharterOCC CharterMiCAGENIUS
_ATTESTED/
_NEXT/

Compliance

FAQ

Questions, answered

01 / WHO PERFORMS YOUR PENETRATION TESTS?

Independent external testers, annually and after major changes, with results feeding a documented remediation workflow. Formance also retains an external virtual CISO.

02 / CAN WE FEED YOUR LOGS INTO OUR SIEM?

Yes. Audit logs auto-sync to customer SIEMs, and platform logs and traces export to any OpenTelemetry-compatible backend.

03 / WHERE IS DATA STORED?

In the region you choose, in a dedicated AWS account (cloud) or on your own infrastructure (self-hosted). Backups replicate only within the same jurisdiction.

04 / HOW DO WE RUN OUR SECURITY REVIEW?

Start at trust.formance.com for reports and the sub-processor list, and use InfoSec office hours with the Formance security team for anything deeper.

GET STARTED

Bring your security review

Get the reports, then get your questions answered live: book a demo or visit the trust center.