Skip to content

Security by design for financial technology.

Fellow Data develops technology for organisations operating in environments where security, privacy, governance and operational resilience matter. This is how we approach them.

Our approach

Security principles.

Security is designed into how Fellow Data handles data, access and change, not added at the end.

  • Data protection

    Customer information is handled according to applicable contractual and legal requirements, and collected only where it is needed. See data protection.

  • Encryption

    Encryption in transit and at rest, where technically applicable.

  • Access control

    Access is designed around least privilege: people and services get only the access their role needs.

    • Role-based access control
    • Least privilege
    • Multi-factor authentication
    • Privileged access management
    • Service-account controls
  • Environment isolation

    Customer data and systems are kept apart, where applicable.

    • Tenant isolation
    • Logical data segregation
    • Environment separation
  • Monitoring

    Security monitoring covers the events that matter most.

    • Authentication
    • Privileged activity
    • Anomalous behaviour
    • System events
    • API access
  • Vulnerability management

    We welcome reports of suspected vulnerabilities and handle them under our vulnerability disclosure policy.

Incident response

How we respond to a security incident.

Fellow Data maintains processes designed to identify, investigate, contain and remediate security incidents.

  1. Detect

    Identify a possible incident through monitoring or a report.

  2. Triage

    Assess its severity and scope, and assign an owner.

  3. Contain

    Limit the impact and stop it from spreading.

  4. Investigate

    Establish what happened, how and what was affected.

  5. Remediate

    Remove the cause and fix the weakness.

  6. Recover

    Restore affected systems and confirm they work as expected.

  7. Notify

    Inform affected customers and authorities where legally required.

  8. Post-incident review

    Learn from the incident and improve controls and procedures.

Where legally required, affected customers and authorities will be notified in accordance with applicable requirements.

Operational resilience

Designed with operational resilience in mind.

Fellow Data designs its technology and contractual processes with financial-sector operational resilience requirements in mind, including considerations relevant to ICT third-party risk management where applicable.

For financial entities in the EU, the Digital Operational Resilience Act (DORA) has applied since 17 January 2025 and sets requirements for managing ICT third-party risk. We are happy to discuss what your due diligence needs from us.

Regulation

Regulatory considerations.

Depending on customer location, use case and deployment, relevant frameworks may include the following. The exact obligations depend on the customer's role, jurisdiction and use of the product.

  • GDPR

    EU General Data Protection Regulation.

  • KVKK

    Türkiye's Personal Data Protection Law No. 6698.

  • DORA

    EU Digital Operational Resilience Act.

  • MiFID II

    EU Markets in Financial Instruments Directive.

  • Financial-services regulation

    Rules that apply to your licence and jurisdiction.

  • AI governance requirements

    Rules and guidance on the use of AI.

  • Cybersecurity requirements

    Sector and national security obligations.

  • Outsourcing requirements

    Contractual rules for outsourced technology.

Security questions? Talk to us.

Send us your security questionnaire, or ask about our approach to data protection, access control and AI governance.