Security is at the heart of everything we do
Akoya promotes a safer, more secure method for accessing and sharing financial data.
Our steadfast approach to security
Akoya uses the National Institute of Standards (NIST) Cybersecurity Framework and Center for Internet Security (CIS) principles to guide and establish our overall security program. This includes documented policies, standards, controls, and commitments to satisfy the requirements defined in each policy. The Akoya Information Security team manages our information security policy portfolio and its lifecycle management, including policy creation, changes, approvals, exceptions, and removal.
The goals of Akoya’s cybersecurity and risk program include:
-
Safeguarding the preservation of confidentiality, integrity, and availability of Akoya systems and information
-
Protecting customers, employees, and the Akoya business
-
Ensuring Akoya’s reputation as a trusted service provider is upheld
Security strategy
Our goal in developing and implementing these data security measures is to instill confidence in data providers and data recipients joining Akoya’s data access network and, more broadly, to bring about a safer and more cyber resilient Open Finance ecosystem.
Secure data handling
Intended to protect both our organization and customers against evolving threats, Akoya maintains a policy defining strict requirements for information classification, labeling, handling, monitoring, and disposal (i.e., lifecycle management) for all Akoya data.
Encryption
All data traversing our platform is encrypted in transit using industry standard encryption algorithms. Encryption at rest for customer data is not required because Akoya does not store personal customer data.
Frameworks & architectures
Akoya adheres to industry standards for our systems and infrastructure to ensure that data is protected, users are safe, and businesses can thrive in an open market. Taking into consideration Akoya’s risk appetite, our policies are continuously guided by NIST, CIS, COSO, laws, regulations and industry best practices.
Security models & protocols
Akoya has adopted and integrated several innovative security models and protocols to keep its assets and data safe from unauthorized access.
Zero Trust
Least privilege
Defense in-depth
Trusted for secure financial data access and sharing
Akoya’s approach to third-party risk management
Akoya’s data access network is inclusive of the entire financial services industry and serves fintechs, data aggregators, financial institutions, and credit unions. In this highly regulated yet diverse ecosystem, Akoya’s third-party risk management services ensure both network data providers and data recipients receive a comprehensive, transparent, streamlined solution.
Frequently asked questions
What security frameworks does Akoya use?
Akoya's security program is built on the NIST Cybersecurity Framework and Center for Internet Security (CIS) principles, with additional alignment to COSO and to applicable laws, regulations, and industry best practices. These frameworks guide Akoya's documented policies, controls, and ongoing security commitments across the confidentiality, integrity, and availability of all systems and data.
What security certifications does Akoya hold?
Akoya is SOC 2 Type 2 certified, which is independently audited annually against the AICPA's Trust Services Criteria. The platform is also aligned with NIST and FIPS-140 standards, which govern the requirements for cryptographic modules used to protect sensitive data.
How does Akoya encrypt data?
All data through the Akoya platform is encrypted in transit using industry-standard algorithms. Encryption at rest is not required because Akoya's passthrough architecture does not store any consumer financial data.
What is Zero Trust, and how does Akoya implement it?
Zero Trust requires every user, device, and request to be authenticated, authorized, and continuously validated before accessing applications and data, regardless of network location. Akoya's platform is built on this framework, replacing implicit trust with ongoing verification across the entire system.
How do least privilege and defense-in-depth work together in Akoya's security model?
Least privilege grants users and systems only the minimum access required for their specific task or job function. Akoya applies this principle across its access controls, reducing the impact of any single compromised account or credential.
How does Akoya assess and monitor third-party security risk?
Every fintech, data aggregator, and financial institution must meet mandatory security controls and policies before joining the Akoya network. All participants undergo annual re-certification, and Akoya performs continuous monitoring of business and security risks throughout the relationship.
How does Akoya's passthrough architecture reduce security risk?
Because Akoya does not copy, store, or retain consumer financial d\ata or login credentials, there is no long-term data repository to attack. This dramatically reduces the attack surface. Because no consumer financial data is stored, there is no long-term repository to compromise.
How does Akoya keep its security program current?
Akoya's policies and controls are continuously guided by evolving frameworks (NIST, CIS, COSO), changes in laws and regulations, and industry best practices. The platform undergoes annual SOC 2 Type 2 audits, and network participants are subject to continuous risk monitoring.
How does Akoya integrate with our existing systems?
Akoya connects to your institution's existing infrastructure, fitting into your current authentication and data access patterns without requiring you to rebuild core systems. The integration layer sits between your internal environment (customer portal, mobile banking, authentication, and data systems) and the Akoya-hosted platform, which then manages all connectivity to third parties. Integration options are flexible to accommodate unique tech stacks, and Akoya's team supports the technical implementation from start to finish.
What happens as regulations and standards change?
This is one of the core reasons institutions choose a managed solution over building in-house. Akoya continuously updates the platform as FDX technical standards evolve and as CFPB regulations develop, so your institution stays compliant without having to track, interpret, and implement changes internally. This includes updates to API specifications, performance requirements, policy and procedure templates, and security review methodologies. Your team gets the benefit of an expert team monitoring the regulatory landscape full-time, without carrying that burden yourself.
