Security by design
Operational and technical safeguards built into infrastructure, access management, and transaction oversight.
Overview
Settla is building cross-border financial infrastructure designed to meet enterprise risk, security, and regulatory expectations — with compliance embedded by design, not added as an afterthought.
This Trust Center outlines how we approach security, compliance, and operational risk across our platform. It exists to reduce enterprise procurement friction, pre-empt security and compliance questionnaires, signal operational maturity, and anchor credibility in structure — not hype.
Operational and technical safeguards built into infrastructure, access management, and transaction oversight.
Regulatory and compliance considerations embedded directly into transaction structuring and execution workflows.
Audit-ready processes, documented execution, and a procurement-ready posture across complex corridors.
Trained specialists review exceptions and have the authority to escalate or halt execution when warranted.
Security
Security at Settla is treated as an operational discipline integrated into infrastructure design, access management, transaction oversight, and data protection.
Data is protected at every stage of the transaction lifecycle using encryption, segmentation, and industry-standard security controls.
Access is granted based on role and responsibility, ensuring least-privilege access and strong separation of duties.
Systems and transactions are continuously monitored to detect anomalies, enforce policies, and ensure operational integrity.
Sensitive data is handled with strict controls, secure environments, and defined retention policies.
Transaction details are received and validated through secure intake channels.
Counterparties and transaction parameters are verified against internal and external controls.
Transactions are routed through approved corridors based on risk, policy, and operational rules.
Real-time monitoring ensures activity remains within policy and risk thresholds.
Settlement is executed securely with reconciliation and confirmation.
All actions are securely logged to ensure traceability, accountability, and audit readiness.
Compliance
Settla structures its operations to support regulatory compliance across the jurisdictions in which it operates. Compliance considerations are embedded into execution workflows to ensure legitimacy, transparency, and long-term scalability.
We monitor transactions in real time and conduct periodic reviews to detect anomalies, assess risk, and ensure alignment with applicable requirements.
We maintain robust KYB procedures to verify business legitimacy, ownership structure, and the ongoing risk profile of counterparties.
Corridors are evaluated based on regulatory landscape, counterparty risk, and operational complexity to ensure reliable outcomes.
All execution and settlement activities are documented with clear audit trails to support transparency and traceability.
We support our enterprise partners with the documentation, transparency, and controls needed to meet internal risk and procurement requirements.
We provide the information and evidence needed to support security and compliance reviews efficiently.
Our policies, controls, and processes are designed to meet enterprise and regulatory expectations.
We maintain organized, up-to-date documentation to streamline due diligence and vendor assessments.
We align with enterprise procurement standards and support questionnaires and assessments.
Framework
Trust at Settla is governed by a clear operating framework — the Settla CREED.
This framework defines how we design systems, structure transactions, and scale responsibly across jurisdictions.
Settla embeds regulatory and compliance considerations directly into transaction structuring, execution workflows, and operational processes.
Customer Outcomes:
We prioritize execution certainty over theoretical speed.
Customer Outcomes:
Settla aligns incentives across clients, partners, and liquidity providers.
Customer Outcomes:
Systems and processes designed for enterprise expectations.
Customer Outcomes:
Human judgment, compliant execution, and secure technology working together.
Customer Outcomes:
Risk Management
Settla manages operational and financial risk through structured execution controls and defined decision pathways.
Each corridor is evaluated for regulatory, counterparty, liquidity, and operational risk factors before execution.
Execution rules, thresholds, and controls are established in advance to ensure consistency and risk alignment.
Trained professionals review exceptions and have the authority to escalate or halt execution when warranted.
All actions, decisions, and system events are recorded to ensure full traceability and audit readiness.
Transaction details are captured and validated against basic criteria.
Regulatory and policy checks are performed before proceeding.
Corridor risk, counterparty, and liquidity are validated for suitability.
Optimal route is selected and liquidity is confirmed for execution.
Settlement instructions are issued and counterparties are aligned.
Transactions are monitored in real time and reported for transparency.
Assurance
Settla is committed to achieving and maintaining internationally recognized certifications that reflect our dedication to security, privacy, and operational excellence. Our assurance roadmap reflects our transparency and long-term commitment to enterprise-grade standards.
We are working toward SOC 2 Type II certification to validate the effectiveness of our controls across security, availability, processing integrity, confidentiality, and privacy.
Progress
65%
Focus Areas
We are pursuing ISO 27001 certification to strengthen our information security management system (ISMS) and align with global best practices.
Progress
55%
Focus Areas
We are aligning with GDPR principles to ensure appropriate data protection, privacy rights, and responsible data handling across our operations.
Progress
60%
Focus Areas
Settla does not claim certifications before completion or formal audit validation. We believe in earning trust through verifiable outcomes, independent assessments, and continued accountability.
Responsible Disclosure
Settla is committed to maintaining the security, integrity, and reliability of our platform. We welcome security researchers and responsible disclosure of potential vulnerabilities.
This policy applies to all Settla systems, services, applications, and infrastructure, including associated environments and subdomains. We appreciate researchers who help us improve by reporting potential security vulnerabilities.
Please submit all security findings to our security team using the secure email listed below. Provide as much detail as possible to help us reproduce and assess the issue. Do not access, modify, or delete data that does not belong to you.
We acknowledge all valid reports within 48 hours. Initial triage is typically completed within 5 business days. We will keep you informed throughout the process and provide updates at key milestones.
We follow industry-standard safe harbor principles. Good faith research conducted in accordance with this policy will not result in legal action. We ask that you do not publicly disclose the vulnerability until we have had a reasonable time to address it.
We value clear, professional, and respectful communication. Researchers will be treated as partners in helping us strengthen our security posture.
Share details of the potential vulnerability via our secure reporting channel.
We validate and assess the report and determine impact and priority.
We address the issue and implement fixes with rigorous testing.
We confirm resolution and communicate outcomes with the researcher.
Use this email for all security reports and related inquiries.
For time-sensitive or high-impact matters, please include [ESCALATION] in the subject line. We will prioritize accordingly.
We acknowledge all reports within 48 hours and aim to provide an initial response within 5 business days.
FAQs
Find answers to common questions about Settla's security, compliance, and operational assurance practices.
The Settla Trust Framework is our commitment to secure operations, regulatory alignment, and enterprise-grade controls. It spans security, risk management, compliance, and transparency across our platform and partner network.
Settla is actively progressing toward SOC 2 Type II and ISO 27001 as part of our security and compliance roadmap. We do not claim certifications before they are formally completed.
Risk is managed through corridor-specific assessments, structured execution workflows, defined parameters, and human oversight with the authority to escalate or halt execution when warranted.
Yes. Settla supports enterprise due diligence, including procurement reviews, security questionnaires, and compliance discussions through our Security & Compliance team.
We embed compliance directly into transaction structuring and execution workflows — not as an afterthought. We treat compliance as an ongoing operational requirement.
Settlement is executed with predefined parameters, real-time monitoring, reconciliation, confirmation, and full audit logging for traceability and accountability.
Contact
Whether you're exploring a corridor, evaluating a partnership, or running a security or compliance review — send us a message and the right specialist will be in touch.
Questions about FX execution, supported corridors, settlement, or pricing for your business.
Banks, liquidity providers, infrastructure platforms, and ecosystem partners — we'd love to hear from you.
Enterprise security reviews, vendor due diligence, or responsible disclosure of a vulnerability.
All communications are handled securely and confidentially.
We aim to acknowledge all inquiries within 48 hours.
Structured processes ensure efficient and secure handling of requests.
For urgent or sensitive matters, we provide a direct escalation pathway.