generated: '2026-08-17' method: searched probe: true url: https://www.fipto.com/company/compliance also: https://www.fipto.com/company/security note: >- Fipto runs no third-party trust portal (trust.fipto.com and security.fipto.com do not resolve), but it publishes two first-party pages that serve the same purpose and name real certifications and licence numbers: a Compliance Center and a Security Center. The mechanical probe (probe-security-programs.py) missed both because it only checks /trust, /security and /compliance at the domain root — Fipto serves them under /company/. Recorded here from a direct read. certifications: ['ISO/IEC 27001:2022'] licences: - 'Payment Institution — ACPR (Banque de France), CIB 17908' - 'MiCA CASP — AMF (France), authorisation A2026-009' - 'VASP registration — Luxembourg' controls_published: - 100% segregation of client funds - Regular third-party penetration testing - 24/7 infrastructure monitoring and alerting - Multi-factor authentication, multi-signature validation, role-based permissions, session timeouts - End-to-end encryption in transit and at rest - Daily backups, quarterly recovery testing, automated failover, redundant cloud hosting - GDPR-aligned data deletion policies - Mandatory KYC/KYB for AML/CFT and sanctions compliance policies: - {name: Custody / Conservation Policy, url: 'https://www.fipto.com/legal/conservation-policy'} - {name: Order Execution Policy, url: 'https://www.fipto.com/legal/order-execution-policy'} - {name: Conflict of Interest Policy, url: 'https://www.fipto.com/legal/conflict-of-interest-policy'} - {name: Complaints, url: 'https://www.fipto.com/legal/complaints'} - {name: Terms and Conditions, url: 'https://www.fipto.com/legal/terms-and-conditions'} - {name: Privacy Policy, url: 'https://www.fipto.com/legal/privacy'} evidence: - {source: 'https://www.fipto.com/company/compliance', http_status: 200, keywords: [mica, casp, acpr, payment institution, 'iso/iec 27001:2022', aml/cft, compliance center]} - {source: 'https://www.fipto.com/company/security', http_status: 200, keywords: [iso 27001, penetration testing, segregated, encryption, mfa]} - {source: 'https://trust.fipto.com', http_status: 0, note: does not resolve} - {source: 'https://security.fipto.com', http_status: 0, note: does not resolve} vulnerability_disclosure: published: false note: >- Neither page — nor any page in the sitemap — publishes a vulnerability disclosure policy, a bug bounty program, a responsible-disclosure address or a security@ contact, and /.well-known/security.txt returns 404 on every host. For an ISO 27001-certified, dual-licensed payment institution this is the most conspicuous gap in an otherwise strong posture. No `Security` or `VulnerabilityDisclosure` pointer is emitted in apis.yml, because there is nothing published to point at.