Compliance, security & standards

Documentation-ready controls for bank and payment-provider review

This page sets out our security standards, data-protection posture, AML/KYC technology policy and the boundary between our software services and regulated financial activity.

Regulatory status disclaimer

FinPayOne Ltd is a software engineering and data processing company. We provide technology, integration layers and infrastructure to businesses and to licensed financial institutions. FinPayOne is not a bank, is not an electronic money institution, and does not hold, transmit or settle client funds. All regulated payment execution is performed by our clients' licensed partners.

SIC 62012

Business & domestic software development

SIC 63110

Data processing, hosting & related activities

SIC 66190

Activities auxiliary to financial intermediation

SIC 64999

Financial technology infrastructure enablement

Security standards

Technical and organisational measures

Aligned to ISO/IEC 27001 control families and reviewed annually.

Encryption

TLS 1.3 enforced on all external endpoints with HSTS. AES-256 encryption at rest with envelope encryption and managed KMS key rotation. Secrets are stored in a managed vault and never in source control.

Access control

Single sign-on with mandatory multi-factor authentication, role-based least-privilege permissions, time-bound production access, and full audit logging of privileged actions.

Infrastructure & resilience

Immutable infrastructure as code, segregated development, staging and production environments, automated backups with tested restores, and documented disaster-recovery runbooks.

Personnel & assurance

Background-screened engineers, annual security training, signed confidentiality agreements, independent annual penetration testing and continuous dependency scanning.

AML / KYC technology policy

Where our software ends and regulated decision-making begins

Due diligence pack

For onboarding with banks, acquirers and payment providers we can supply: certificate of incorporation, VAT registration, proof of registered address, director identification, signed client contracts and invoices, technical scope documents, information security policy, data processing agreement and sub-processor list.