Security & trust

Your money.
Your bank. Always.

Remti is an Open Banking orchestrator, not a custodian. We never take possession of your funds — every payment is authorised by you, executed by your bank.

How your money moves

Three steps.
Never through us.

Every payment is a direct instruction from your bank account to your supplier's bank account. Remti orchestrates the handshake — we never hold, route, or process funds.

1
Your business bank
Barclays ·••4829
↓ Faster Payments, 1–2 hrs
2
Supplier's bank
Direct settlement
Remti orchestrates · never holds funds
Four pillars

Security, by default.

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit. Bank credentials never touch our servers — authorisation stays in your bank's app.

FCA authorised partner

We work exclusively with FCA-authorised EMIs. Every payment is PSD2-compliant with strong customer authentication.

Every action audited

Immutable log of who did what, when. Exportable for your auditor, retained for 7 years on enterprise plans.

Approve with 2FA

Every payment above your threshold requires a second factor: your bank's app, TOTP, or hardware key.

Confirmation of Payee

We check account holder names against sort codes before every payment. Misnamed beneficiary? Flagged before send.

Your data, your control

Granular permissions by role. Delete your data any time — we honour erasure within 30 days under UK GDPR.

Compliance

Audited. Certified. Renewed.

SOC
2 · II

SOC 2 Type II

Annual audit · Report on request

ISO
27001

ISO 27001

Certified 2024 · BSI

GDPR

UK GDPR & DPA

ICO registered · DPA signed on request

PSD2

PSD2 / Open Banking

Strong customer auth · all payments

99.98%
Uptime last 12 months
0
Funds lost or delayed
<2m
Median fraud check time
24/7
Security on-call
The small print, in plain English

What's under the hood.

Hosted in UK & EU

AWS London (eu-west-2) primary, Dublin failover. Data never leaves UK/EU without your consent.

AWS

Point-in-time backups

Every 15 minutes, encrypted, retained 90 days. RPO 15 min, RTO 4 hrs.

RPO 15m

Role-based access

Admin, Manager, Assistant, Read-only. Scoped by entity, supplier category, or amount.

RBAC

SSO & SCIM provisioning

Okta, Google Workspace, Azure AD. Auto-deprovision on leaver events.

Scale plan

Data portability

Export every invoice, payment, and approval to CSV, JSON, or PDF. Your data is never locked in.

Any time

Vulnerability disclosure

Public program. We pay bounties up to £10,000 for responsibly-disclosed issues.

security.txt