Security — Hublio Payments

Engineered for trust.
Audited to prove it.

Payment infrastructure carries other people's money and other people's data. We treat both accordingly: a zero-trust architecture, defence in depth from the network to the ledger, and independently certified management systems for information security and privacy.

ISO/IEC 27001 certified
ISO/IEC 27701 certified
PCI DSS aligned
ISO/IEC 27001ISO/IEC 27701Zero-TrustmTLSHSM-Backed KeysTenant IsolationRBACAudit TrailPCI DSS AlignedDORA-ReadyISO/IEC 27001ISO/IEC 27701Zero-TrustmTLSHSM-Backed KeysTenant IsolationRBACAudit TrailPCI DSS AlignedDORA-Ready
01 — Certifications

Independently audited.

Hublio Research is certified to ISO/IEC 27001 and ISO/IEC 27701. Certification means an accredited, independent body has audited how we manage security and privacy — not once, but on a recurring cycle — and verified that the management systems behind this platform meet the international standard.

ISO/IEC 27001

Information security, as a managed system.

ISO/IEC 27001 is the international standard for information security management systems (ISMS). It requires an organisation to identify its security risks systematically, apply controls proportionate to them, document how those controls operate, and improve them continuously — with an accredited auditor verifying the whole system, on-site, on a recurring cycle.

In practice: security at Hublio is not a set of ad-hoc measures. It is a governed, risk-based programme with defined ownership, measured performance and external verification.

Risk-based controlsRecurring independent auditsContinual improvement
ISO/IEC 27701

Privacy, held to the same discipline.

ISO/IEC 27701 applies the same management-system rigour to privacy. It governs how personally identifiable information is collected, processed, protected and deleted — with distinct controls for the roles of data controller and data processor, and a published mapping to GDPR obligations.

In practice: the personal data flowing through a Hublio deployment — customer identities, KYC records, transaction parties — is managed under an audited privacy programme, not just a privacy policy.

Controller & processor controlsGDPR-mappedPrivacy by design
What certification means for you

Due diligence, simplified.

When your risk, compliance or procurement teams assess Hublio, they are not relying on our self-assessment. They can rely on the certificates — evidence that an accredited third party has examined our security and privacy management and found it conformant.

For regulated institutions, that shortens vendor risk assessment, supports your own regulatory obligations, and gives your auditors a recognised, international reference point instead of a bespoke questionnaire.

Accredited third-party verificationRecognised by regulators worldwide
02 — Defence in depth

Five layers between
the outside and the money.

No single control is trusted to hold. Every request crosses independent layers of defence — each monitored, each auditable — before it can touch data or move a cent.

Operations & monitoring full audit trail · alerting · incident response
Network & infrastructure zero-trust · mTLS · segmentation
Identity & access OAuth 2.0 · RBAC · approval workflows
Application hardened services · tenant isolation
Data encrypted in transit and at rest · HSM-backed keys
Verified by
ISO/IEC 27001
ISO/IEC 27701
PCI DSS Aligned
Recurring Audits
03 — Security domains

Everything a payments stack
should cover.

Security in a payment platform is not one discipline but six — and each one is a first-class part of how Hublio Payments is built, deployed and operated.

Identity & access

Every actor verified. Every action scoped.

  • OAuth 2.0 with certificate-bound tokens; OIDC for user identity
  • Granular role-based access for ops, risk, finance and compliance
  • Approval workflows for sensitive parameters
  • Enterprise SSO integration for institutional deployments
Data protection

Encrypted, isolated, under your keys.

  • Encryption in transit and at rest
  • HSM-backed keys and dedicated secrets vaulting
  • Bring-your-own key management supported
  • Strict tenant data isolation, per-tenant compliance posture
Network & infrastructure

Zero-trust, everywhere.

  • mTLS for all B2B and inter-service traffic
  • Segmented environments, least-privilege by default
  • Runs inside your perimeter — cloud, on-premise or sovereign
  • Data residency configured per deployment
Secure development

Security in the lifecycle, not after it.

  • Security review built into the development lifecycle
  • Dependency and vulnerability management as routine practice
  • Separated environments from development to production
  • Changes audited, reviewable and reversible
Monitoring & response

Seen, scored, answered.

  • Full audit trail across platform and console
  • Inline AML, sanctions screening and fraud scoring on every transaction
  • Suspicious activity held, scored, escalated or released
  • Defined incident response under the certified ISMS
Resilience & continuity

Built to stay up.

  • Multi-AZ, multi-region capable architecture
  • 99.99% uptime target, designed and measured
  • Horizontally scalable, cloud-native services
  • Continuity planning governed under ISO/IEC 27001
04 — Regulatory frame

Built for the rules
you answer to.

The platform is designed for the regulatory perimeter our clients operate in — with compliance primitives in the architecture, not retrofitted. Certification to ISO/IEC 27001 and 27701 gives your own regulators and auditors a recognised reference point.

PSD3 / PSRAMLD6DORAeIDAS 2.0GDPRPCI DSS alignedISO 20022Verification of Payee
05 — Shared responsibility

Self-hosted means honest boundaries.

Because Hublio Payments runs in your environment, security is a defined partnership — not a black box. We deliver the hardened platform: secure defaults, zero-trust architecture, audited security and privacy management, and a full audit trail.

You retain what should be yours: the perimeter, the keys, the identity stack and the data residency decisions. The boundary between the two is documented per deployment — so your auditors always know exactly who is accountable for what.

Hardened platform, secure defaultsYour keys, your perimeter, your data

Security due diligence to run?
Bring your hardest question.

Our team will walk your risk, compliance and engineering people through the architecture, the certifications and the deployment model that fits your perimeter.