Security by design for financial technology.
Fellow Data develops technology for organisations operating in environments where security, privacy, governance and operational resilience matter. This is how we approach them.
Our approach
Security principles.
Security is designed into how Fellow Data handles data, access and change, not added at the end.
Data protection
Customer information is handled according to applicable contractual and legal requirements, and collected only where it is needed. See data protection.
Encryption
Encryption in transit and at rest, where technically applicable.
Access control
Access is designed around least privilege: people and services get only the access their role needs.
- Role-based access control
- Least privilege
- Multi-factor authentication
- Privileged access management
- Service-account controls
Environment isolation
Customer data and systems are kept apart, where applicable.
- Tenant isolation
- Logical data segregation
- Environment separation
Monitoring
Security monitoring covers the events that matter most.
- Authentication
- Privileged activity
- Anomalous behaviour
- System events
- API access
Vulnerability management
We welcome reports of suspected vulnerabilities and handle them under our vulnerability disclosure policy.
Incident response
How we respond to a security incident.
Fellow Data maintains processes designed to identify, investigate, contain and remediate security incidents.
Detect
Identify a possible incident through monitoring or a report.
Triage
Assess its severity and scope, and assign an owner.
Contain
Limit the impact and stop it from spreading.
Investigate
Establish what happened, how and what was affected.
Remediate
Remove the cause and fix the weakness.
Recover
Restore affected systems and confirm they work as expected.
Notify
Inform affected customers and authorities where legally required.
Post-incident review
Learn from the incident and improve controls and procedures.
Where legally required, affected customers and authorities will be notified in accordance with applicable requirements.
Operational resilience
Designed with operational resilience in mind.
Fellow Data designs its technology and contractual processes with financial-sector operational resilience requirements in mind, including considerations relevant to ICT third-party risk management where applicable.
For financial entities in the EU, the Digital Operational Resilience Act (DORA) has applied since 17 January 2025 and sets requirements for managing ICT third-party risk. We are happy to discuss what your due diligence needs from us.
Regulation
Regulatory considerations.
Depending on customer location, use case and deployment, relevant frameworks may include the following. The exact obligations depend on the customer's role, jurisdiction and use of the product.
GDPR
EU General Data Protection Regulation.
KVKK
Türkiye's Personal Data Protection Law No. 6698.
DORA
EU Digital Operational Resilience Act.
MiFID II
EU Markets in Financial Instruments Directive.
Financial-services regulation
Rules that apply to your licence and jurisdiction.
AI governance requirements
Rules and guidance on the use of AI.
Cybersecurity requirements
Sector and national security obligations.
Outsourcing requirements
Contractual rules for outsourced technology.
Keep exploring.
AI governance
Fellow Data's responsible AI principles and agent control framework: human accountability, oversight, permissions, risk limits, logging and transparency.
Explore AI governanceData protection
Fellow Data's approach to GDPR and Türkiye's KVKK: data processing, international transfers, retention, security and how to make a data subject request.
Explore data protectionTechnology
Inside Fellow Data: data ingestion, quantitative risk analytics, AI reasoning, agent orchestration, a policy engine and audit logs, connected through APIs.
Explore technology
Security questions? Talk to us.
Send us your security questionnaire, or ask about our approach to data protection, access control and AI governance.