Security & Trust

Enterprise security,
built in — not bolted on

Ironledge is designed from the ground up with zero-trust architecture, end-to-end encryption, and industry-leading certifications. Your data, and your customers' data, is always protected.

Certifications & Authorisations

Regulated, certified
and independently verified

We hold the highest level of financial and information security credentials available.

FCA

FCA Authorised

Fully authorised Account Information Service Provider (AISP) and Payment Initiation Service Provider (PISP) under PSD2.

ISO

ISO 27001 Certified

Independently audited information security management system covering all data processing, storage, and transmission.

PSD2

PSD2 Compliant

Full Strong Customer Authentication (SCA), eIDAS certificates, and Qualified Web Authentication Certificate (QWAC) implementation.

GDPR

GDPR Ready

Data Protection Officer appointed, Privacy by Design enforced, full DSAR workflow, and data processing agreements available for all customers.

Security Architecture

Six pillars of our
security programme

Every layer of our platform is hardened against the full threat landscape facing financial infrastructure providers.

🔒

Zero-Trust Architecture

Every service-to-service call is authenticated and authorised independently. No implicit trust, even within our own network perimeter.

🔑

End-to-End Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). API keys and tokens never stored in plaintext — always hashed and salted.

🛡

Penetration Testing

External CREST-accredited penetration tests conducted quarterly. All critical findings remediated within 72 hours. Full CVE disclosure programme.

👁

24/7 Threat Monitoring

SIEM platform with real-time anomaly detection, automated incident response playbooks, and a dedicated security operations team.

📋

Immutable Audit Logs

Every API call, data access event, and consent action is logged immutably. Full audit trail available for regulatory inspections and customer reviews.

🔄

Disaster Recovery

Multi-region active-active deployment with RPO < 1 minute and RTO < 5 minutes. Business continuity plan tested biannually. 99.99% SLA guaranteed.

99.99%
API Uptime SLA
<72h
Critical Finding Remediation
256-bit
AES Encryption at Rest
0
Confirmed Data Breaches (lifetime)
Security Questions?

Request our full
security documentation

Enterprise customers can request our ISO 27001 certificate, penetration test summary, and security questionnaire responses.

Responded to within 1 business day · NDA available · Dedicated security contact for enterprise