Fipto · Trust Center

Fipto Trust Center

Trust center

Fipto maintains a public trust center documenting ISO/IEC 27001:2022 compliance.

CompanyBlockchainPaymentsStablecoinsBankingTreasuryCross-Border PaymentsDigital CurrencyFintechWallets
Trust center: https://www.fipto.com/company/compliance

Certifications & Compliance

ISO/IEC 27001:2022

Source

Trust Center

Raw ↑
generated: '2026-08-17'
method: searched
probe: true
url: https://www.fipto.com/company/compliance
also: https://www.fipto.com/company/security
note: >-
  Fipto runs no third-party trust portal (trust.fipto.com and security.fipto.com do not resolve), but
  it publishes two first-party pages that serve the same purpose and name real certifications and
  licence numbers: a Compliance Center and a Security Center. The mechanical probe
  (probe-security-programs.py) missed both because it only checks /trust, /security and /compliance at
  the domain root — Fipto serves them under /company/. Recorded here from a direct read.
certifications: ['ISO/IEC 27001:2022']
licences:
- 'Payment Institution — ACPR (Banque de France), CIB 17908'
- 'MiCA CASP — AMF (France), authorisation A2026-009'
- 'VASP registration — Luxembourg'
controls_published:
- 100% segregation of client funds
- Regular third-party penetration testing
- 24/7 infrastructure monitoring and alerting
- Multi-factor authentication, multi-signature validation, role-based permissions, session timeouts
- End-to-end encryption in transit and at rest
- Daily backups, quarterly recovery testing, automated failover, redundant cloud hosting
- GDPR-aligned data deletion policies
- Mandatory KYC/KYB for AML/CFT and sanctions compliance
policies:
- {name: Custody / Conservation Policy, url: 'https://www.fipto.com/legal/conservation-policy'}
- {name: Order Execution Policy, url: 'https://www.fipto.com/legal/order-execution-policy'}
- {name: Conflict of Interest Policy, url: 'https://www.fipto.com/legal/conflict-of-interest-policy'}
- {name: Complaints, url: 'https://www.fipto.com/legal/complaints'}
- {name: Terms and Conditions, url: 'https://www.fipto.com/legal/terms-and-conditions'}
- {name: Privacy Policy, url: 'https://www.fipto.com/legal/privacy'}
evidence:
- {source: 'https://www.fipto.com/company/compliance', http_status: 200,
   keywords: [mica, casp, acpr, payment institution, 'iso/iec 27001:2022', aml/cft, compliance center]}
- {source: 'https://www.fipto.com/company/security', http_status: 200,
   keywords: [iso 27001, penetration testing, segregated, encryption, mfa]}
- {source: 'https://trust.fipto.com', http_status: 0, note: does not resolve}
- {source: 'https://security.fipto.com', http_status: 0, note: does not resolve}
vulnerability_disclosure:
  published: false
  note: >-
    Neither page — nor any page in the sitemap — publishes a vulnerability disclosure policy, a bug
    bounty program, a responsible-disclosure address or a security@ contact, and
    /.well-known/security.txt returns 404 on every host. For an ISO 27001-certified, dual-licensed
    payment institution this is the most conspicuous gap in an otherwise strong posture. No
    `Security` or `VulnerabilityDisclosure` pointer is emitted in apis.yml, because there is nothing
    published to point at.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fipto-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.