Security & Compliance
https://mambu.com/en/security-and-complianceMambu's Security & Compliance offering ensures that its cloud banking platform meets rigorous security and compliance standards, verified by external certifications and audits. The platform is designed to protect customer data, support regulatory requirements, and provide transparency and control to customers.
Added
Product Overview
The Mambu platform lives up to state of art security standards as verified and assured by an external certification body.
Detailed Description
Mambu's Security & Compliance offering ensures that its cloud banking platform meets rigorous security and compliance standards, verified by external certifications and audits. The platform is designed to protect customer data, support regulatory requirements, and provide transparency and control to customers.
Key Features
- Continuous internal security tests and multiple annual external penetration tests covering network and web application vulnerabilities (OWASP Top 10).
- Publicly available APIs and data dictionary; customers can automate backup retrieval.
- Security-in-depth, need-to-know, and least-privilege principles with preventive, detective, and mitigative controls.
- Incident response plans with 24/7 on-call staff.
- Customer data processed in AWS data centres with extensive certifications.
- Dedicated deployments for increased isolation and control.
- APIs to implement PSD2 regulation for open banking.
- Complete audit rights for customers and regulators.
- SLAs for uptime and resolution times; regularly tested disaster recovery and business continuity plans.
- Security embedded throughout the software development lifecycle (SDLC).
Documentation
View DocumentationDetailed Sections
Security & compliance
The Mambu platform lives up to state of art security standards as verified and assured by an external certification body.
Here's how we do it
- Continuous internal security tests and multiple annual external penetration tests (OWASP Top 10).
- Public APIs and data dictionary; automated backup retrieval.
- Security-in-depth, need-to-know, least-privilege principles.
- Incident response plans and 24/7 on-call staff.
Infrastructure & regulation
- AWS Partner Network member in Financial Services Competency program.
- Audited in AWS Well Architected Program for security best practices.
- Customer data processed in AWS data centres with extensive certifications.
- SOC 1 (Type 1 and 2) and SOC 2 (Type 1 and 2) compliant.
- ISO/IEC 27001 certified ISMS.
Data protection & privacy compliance
Mambu is dedicated to ensuring the protection of personal data entrusted by customers.
- Dedicated deployments for increased isolation and control.
- APIs for PSD2 regulation and open banking.
- Complete audit rights for customers and regulators.
- SLAs for uptime and resolution times; disaster recovery and business continuity plans.
- Security embedded in all SDLC stages.
Customer control, Global data protection programme, Data protection team
- Customers retain control of personal data processed by Mambu.
- Transparency on sub-processors, data processing locations, and cross-border data transfer mechanisms.
- Global data protection programme aligns with GDPR.
- Dedicated data protection team and Data Protection Officer.
Vulnerability Disclosure Program
Provides detailed information on how to submit a report about security and vulnerability issues. Public disclosure is discouraged until the issue is addressed.
