Security

At Ozone API security is our top priority. It has been embedded into our culture, our development process, and our technology from day one.  

Ensuring trust

Trust and security are at the heart of open banking, and our technology plays a key part. We adopt a transparent approach with our clients to earn that trust, and back it up with industry standards and external attestation.

Measures:

Encryption

Industry-leading encryption technology is used across all our systems to protect data in transit, at rest, and in-use.

Minimisation

We only store what is necessary, and securely delete it as soon as it’s no longer needed. Sensitive data is redacted from our logs and never stored. 

Governance

Our management systems build ‘secure-by-default’ practices into everything we do. All of our team are trained and background checked.

Operations

From design to deployment we continuously scan and test our production environments for threats. Our cloud environment is monitored 24/7 for issues.

Trust Center

If you want to know more about our security, and related certifications, policies, and procedures visit our Trust Center for realtime information.

Access now

Certificates

IASME Cyber Essentials
ISO/IEC 27001:2022
SOC 2 Type 2 unqualified opinion attestation

Responsible
disclosure

If you believe you have discovered a potential security issue in the Ozone API platform, we encourage you to disclose it to us privately at security@ozoneapi.com

While we greatly appreciate reports regarding security vulnerabilities, at this time we do not offer monetary compensation for reports.