Trust Center
Moneytree is a privacy-first financial platform. This site documents our security controls, compliance certifications, governance practices, and AI policy — so you can verify our commitments, not just read about them.
ISO/IEC 27001 certified, TRUSTe Privacy Accredited across three products, and registered with Japan's FSA as an electronic payment intermediary.
- ISO/IEC 27001
- TRUSTe Certified
- FSA Registered
5 core ISMS documents, 20 operational policies, and a dedicated security tooling stack — including CrowdStrike, Okta, and AWS Security Hub — enforcing controls across the organisation.
- ISO/IEC 27001 ISMS
- 20 operational policies
- 7 security tools
120 security controls mapped to ISO 27001, FISC, and APPI — independently audited annually. Includes an active Bugcrowd bug bounty programme open to external researchers.
- 120 controls
- ISO 27001 · FISC · APPI
- Bug bounty (Bugcrowd)
AI use is governed by a formal policy and a Framework for Responsible AI Use. Sensitive data requires an approved risk review before use with any external AI system.
- Privacy & fairness
- Data classification rules
- Oversight Committee
A transparent log of security incidents affecting Moneytree's systems or customer data. Updated whenever a reportable incident occurs.
- ✓ No incidents in 2025
- ✓ No incidents in 2026
Common questions about security, privacy, data storage, deletion procedures, compliance certifications, and how to report a vulnerability.
- Security
- Privacy & data
- Certifications
Our security team is available to answer questions about our controls, certifications, data handling, or to receive a vulnerability report.