Banking-Grade Security & Compliance | SOC 2 Type 2, ISO 27001
A Platform You Can Trust
Our platform meets state-of-the-art security standards, verified and assured by an external certification body. We address security concerns by offering a trusted platform that minimises security-related friction, ensuring customer engagement remains high.
Best-in-class security services & infrastructure
Leveraging best-in-class security services and advanced infrastructure, Plumery is SOC 2 Type 2 compliant and delivers ISO 27001:2022-certified cybersecurity, proactively managing risks and evaluating the effectiveness of technical and organisational controls through regular internal and external audits.
Security is embedded in all stages of the software development lifecycle (SDLC) – from requirements engineering, programming and QA to deployment, monitoring, alerting and incident management.
99.95% Uptime
Our cloud infrastructure ensures long-term success with continuous monitoring and support, providing multiple fail-safes in the event of outages or bugs.Incident Response
In the event of a security incident, we are fully prepared with incident response plans and 24/7 on-call staff to respond swiftly and effectively.Data Security
We employ principles such as defence-in-depth, need-to-know, and least-privilege to minimise the risk of security incidents from internal or external threats, utilising a range of preventive, detective, and mitigative controls.Accounts and Payments Security
We enforce multi-factor authentication for accessing digital banking accounts, and your customers can enable biometric options like face or touch ID. Our platform includes industry-leading solutions to verify user identities, ensuring compliance with federal KYC and AML regulations.Infrastructure Security
All data is encrypted and securely stored in the cloud. Each of our customers benefits from a dedicated deployment, separate from other Plumery customers.External Pentests
We conduct continuous internal security tests, supplemented by external penetration testing from security researchers multiple times per year.SLAs and business continuity
We provide SLAs for uptime and resolution times on customer inquiries, with disaster recovery procedures and business continuity plans regularly tested.Audit Trail
We capture all events triggered by users, internal, or external services, and present them in a clear, structured format, enabling effective analytics and fraud prevention.