Computools develops FinTech software using secure development practices and security controls appropriate to the product’s architecture, data, users, transaction flows, and risk profile. Depending on project requirements, these can include encryption in transit and at rest, tokenization, secrets and key management, RBAC and MFA, secure API design, audit trails, vulnerability testing, penetration testing, fraud monitoring, and security monitoring.
For payment workflows, solutions can be designed to support applicable PCI DSS requirements rather than assuming that custom software itself automatically provides or guarantees compliance. Regulatory and security requirements related to KYC/KYB, AML, GDPR, Open Banking, data residency, retention, and other applicable frameworks are defined according to the product, jurisdictions, operating model, and responsibilities of the parties involved.
Computools maintains ISO 27001-certified information security management processes. Compliance or certification of a specific FinTech product, however, depends on its architecture, infrastructure, configuration, third-party services, operational processes, and applicable assessment or regulatory requirements.