Security
How we build, operate, and protect the Tranched platform.
Tranched is built on structured finance infrastructure that handles sensitive financial and personal data on behalf of our clients. Security is embedded into every layer of how we build, operate, and manage our platform.
Certifications and Compliance
Tranched is pursuing SOC 2 Type II attestation and ISO/IEC 27001 certification, conducted by an accredited external audit partner. Our security programme is designed to meet the full requirements of both frameworks.
Our compliance programme is backed by a formal Information Security Management System (ISMS) covering all business operations. We comply with UK GDPR and EU GDPR and, where applicable, as a data processor under client Data Processing Agreements.
Access Control
Access to Tranched systems is governed by the principle of least privilege. All personnel are granted only the minimum access required to perform their job function, managed through role-based access controls.
Multi-factor authentication (MFA) is enforced across all systems and required for all privileged access to production infrastructure.
People Security
All personnel undergo background screening prior to being granted access to Tranched systems. Screening is conducted before the commencement of employment or engagement, with enhanced checks applied to roles with privileged access to production infrastructure.
Security awareness training is completed by all personnel at onboarding and annually thereafter. Engineers additionally complete annual secure development training covering the OWASP Top 10 and vulnerability classes.
Secure Development
Security is built into our development process from the start. All code changes are developed in isolated branches, require peer review and automated testing before merge, and follow a documented release checklist before production deployment.
Tranched's systems undergo annual external penetration testing by a qualified security provider.
Vendor and Supply Chain Security
All third-party suppliers are assessed for security risk before onboarding and monitored throughout the relationship. We apply a tiered due diligence process based on each vendor's access to sensitive data and critical systems — requiring SOC 2 Type II or ISO 27001 certification (or equivalent) for our most critical suppliers, and Data Processing Agreements for all vendors processing personal data on our behalf.
Incident Response
Tranched maintains a documented incident response plan covering detection, classification, containment, recovery, and post-incident review.
Security incidents or concerns can be reported to us at contact@tranched.fi.
Business Continuity
Tranched maintains a Business Continuity and Disaster Recovery (BC/DR) plan covering all critical systems and services.
Recovery capabilities are validated through an annual disaster recovery test. As a remote-first company, no single physical location is critical to our operations.
Questions
If you have questions about our security programme or would like to request further information as part of your own due diligence process, please contact us at contact@tranched.fi.