TRUST
“Aligned with what European finance is held to.”
Strawbay is built for regulated finance. Compliance is not a feature we add at the end, it is how we design, operate and show our work, so you can see how data flows, where it lives, and how each integration meets the rules your business answers to.
“EU residency, GDPR by design, controls mapped and ready for certification. It means a customer’s due diligence is a confirmation, not a discovery.”
Andy Kovalov, CTO, Strawbay · Read the article
How we think about it
Compliance by design, not as an afterthought
Our customers are regulated under several directives, and their operations depend on financial data that must stay correct, available and auditable. So we design for that from the first connection: transparent flows you can inspect, stable behaviour at any volume, and controls mapped to the regulations that apply. The result is a platform European finance teams can adopt with confidence, and put through due diligence with nothing to hide.
Compliance and trust at a glance
Where we stand
GDPR by design
Privacy by design and by default: data minimisation, short retention and EU data residency. We act as your data processor under a DPA and support data-subject rights.
EU data residency
Your financial data and our core platform are hosted in the EU, on Google Cloud europe-west1, with no replication outside the EU.
DORA
A DORA-ready ICT third-party provider. We support your DORA obligations with a contractual addendum, Register of Information data, audit and inspection rights, and exit support.
EU AI Act
Our agent layer and AI-assisted reviews run with human oversight and transparency, aligned with the EU AI Act. AI speeds up delivery; people stay in control, and every release to production is a human, authorised step.
ISO 27001
Our controls are already mapped to ISO 27001 Annex A and designed certification-ready. We are prepared to undergo certification when a customer requires it.
ISO 20022
Built to work with ISO 20022, the modern standard for financial messaging, so financial data maps cleanly across the systems we connect.
PEPPOL
E-invoice and document distribution runs over PEPPOL through our distribution partners, reaching the right operator and channel. Our engine is built to handle PEPPOL and other formats in the ISO 20022 standard.
PSD2 / PSD3 / PSR
Strawbay does not initiate or manage payments. Our bank and account connections operate within PSD2 open banking, and the platform is built to align with PSD3 and PSR, so you are well prepared as those capabilities come into scope.
Resilience and continuity
Built to keep running
Automated backups
Code and configuration are backed up automatically every hour, the basis for a one-hour recovery point.
Extensive disaster recovery
Five scenario-based disaster-recovery plans with defined targets. For a cloud-region outage, recovery time four hours and recovery point one hour.
Source-code escrow
Available as a service on request: a monthly source-code deposit with the Swedish Chamber of Commerce, an independent safeguard that keeps your integrations running in a worst case.
For DORA-bound customers
How we support your DORA obligations
As an ICT third-party provider, we make it straightforward to record and rely on Strawbay under DORA: pre-filled Register of Information data so you do not have to send a bespoke questionnaire, an Article 30 contractual addendum, audit and inspection rights, and documented exit and transition support, including monthly source-code escrow with the Swedish Chamber of Commerce.
What we can provide on request
The compliance pack
DPA, ICT Third-Party Provider Information Sheet (Register of Information data), DORA ICT Services Addendum, Incident Notification SLA, Exit and Transition Plan, Business Continuity and Disaster-Recovery summaries, and a penetration-test summary. Shared under NDA where needed.
