Currencycloud takes the security of your data and money very seriously. They are ISO/IEC 27001:2013 compliant and consistently review and enhance their processes and systems to ensure that they remain secure.
The service operates on Amazon Web Services (AWS) which is certified under a number of global compliance programmes which underlines best practices in terms of data centre security.
For the full list of AWS compliance programs see: https://aws.amazon.com/compliance/pci-data-privacy-protection-hipaa-soc-fedramp-faqs/
More information about AWS data centre controls may be found here: https://aws.amazon.com/compliance/data-center/controls/
There are dedicated systems in place to protect against Distributed Denial of Service (DDoS) attacks as well as man-in-the-middle attacks. They use reputable registrars to protect against domain hijacking and “phishing” attacks.
The platform undergoes regular penetration testing and has protection in place against common vulnerabilities like code injection attacks and cross-site scripting attacks.
All network traffic is encrypted at a transport level and confidential information is encrypted at rest. They use best practices in terms of encryption key storage and security.
The platform and operational security is certified under ISO/IEC 27001:2013, the international best practice standard for Information Security Management Controls which is independently audited.
They also comply with best practices and regulations pertaining to the management of personal data under the UK Data Protection Act (DPA), as well as the upcoming European Union General Data Protection Regulation (GDPR).
The platform provides a role based, hierarchical security model with two-step authentication and multi-factor authentication for sensitive systems. All access is logged and audited for suspicious behaviour.
Your money and your data isas important to us as it is to you. Here are some of the things we do to make sure that you can use our services with peace of mind.
Currencycloud is authorised by the Financial Conduct Authorityfor issuing of electronic money and the provision of payment services with FCA registration number 900199.
Currencycloud is registered with FinCEN and is authorized in 22 states to transmit money.
Currencycloud process over $1bn a month on behalf of hundreds of thousands of people and companies.
They comply with best practices and regulations pertaining to the management of personal data under the UK Data Protection Act (DPA), as well as the upcoming European Union General Data Protection Regulation (GDPR).
Currencycloud are ISO/IEC 27001:2013 compliant and have robust processes to protect their systems.
In 2021, Currencycloud was acquired by Visa Inc. By choosing Currencycloud as our e-money provider, we have peace of mind knowing that they are backed by one of the world’s largest capitalised financial institutions.
Your money is held in separate accounts with tier one banks. In the unlikely event of Currencycloud ceasing to exist, your money remains protected. When funds are posted to your account e-money is issued in exchange for these funds by an Electronic Money Institution who we work with – Currencycloud. In line with regulatory requirements Currencycloud safeguards your funds. This means that the money behind the balance you see in your account is held at a reputable bank and, most importantly, is protected for you in the unlikely event of Currencycloud’s, or our insolvency. Currencycloud stops safeguarding your funds when the money has been paid out of your account to your beneficiary’s account.