We pay the utmost attention to the protection of privacy: your personal data will never be shared with any external company except for legal obligations and contract execution. Financial data will never be shared. Our privacy policies can be found here.
We take security seriously. We use a security by design approach, follow international standards and best practices, and work continuously to keep our platform secure. To maintain a high level of protection, we recognise the importance of regular external audits. Today, Soldo is compliant with:
- PCI DSS Level 1. The Payment Card Industry Data Security Standard (PCI DSS) is a data security standard developed by the main payment card networks (MasterCard, Visa, American Express, Discover and JCB) to ensure the security of cardholder data and the systems that host it. Soldo Software Ltd., which provides the group’s software services to all customers, has been accredited annually as a Level 1 Service Provider by the PCI Council since 2017.
- ISO/IEC 27001. This is the international standard for managing information security. It sets out the specifications for an Information Security Management System (ISMS). Adhering to the standard means aligning with globally recognised information security best practices across people, processes and technology. Certification requires an external audit, and regular penetration testing is a pre-condition for successful completion.
- ISO/IEC 9001. Soldo’s ISO/IEC 27001 annual certifications since 2019 demonstrate that all companies in the group are committed to implementing and maintaining an Information Security Management System compliant with the highest international standard. This standard is based on quality management principles including strong customer focus, leadership involvement, the process approach and continual improvement.
- Cyber Essentials Plus. Cyber Essentials is a UK government-backed and industry-supported scheme that helps businesses protect themselves from common online threats. Soldo Software Ltd. and Soldo Financial Services Ltd. have both obtained Cyber Essentials Plus certification, the highest level under the scheme. It involves an external assessor carrying out vulnerability tests.
- HM Government G-Cloud Supplier. Soldo is part of the G-Cloud framework, the UK government’s supplier agreement for cloud computing services for the public sector. The group participated in the G-Cloud 12 framework and was also accepted into the G-Cloud 13 framework in 2022.
From a platform perspective, to protect data and ensure security, we employ:
- 3D Secure. Advanced 3D Secure (3DS) is a supplementary authentication measure that safeguards online transactions for enhanced fraud protection.
- Strong Customer Authentication. We use Secure Customer Authentication (SCA) for multi-factor authentication to increase the security of electronic payments.
- Expenditure filter and lock. Our platform allows you to define who spends what and where, with the option to lock cards if they’re misplaced.
- Continuous security assessments. We test our products with more than 10 security assessments each year. This continual process improves protection. We also work with skilled security researchers worldwide to identify and remove potential vulnerabilities.