Security center

Learn more about all aspects of security at Mynt

Legal & compliance

Mynt has a number of licenses and certifications that together ensure high security and compliance across a range of areas.

E-money license

Mynt has been a registered Swedish e-money institution since 2021 and is supervised by the Swedish Financial Supervisory Authority (Finansinspektionen). This means that we comply with comprehensive banking regulations as set forth by law and by the European Banking Authority (EBA) and Finansinspektionen. It also means that we are obliged to maintain confidentiality regarding our customers and their relationships with us.

DORA

Mynt is compliant with the Digital Operational Resilience Act (DORA), ensuring robust management of digital risks in the financial sector. DORA sets strict and comprehensive requirements for financial institutions and IT service providers to safeguard against cyber threats, operational disruptions, and data breaches. Furthermore, DORA requires deep knowledge and assessment of ICT suppliers.

ISO 27001:2022

Mynt is ISO 27001:2022 certified, demonstrating our commitment to the highest standards of information security. This globally recognized certification ensures that we have a robust management system in place to protect data and systems, manage cybersecurity risks, and implement industry best practices.

GDPR compliant

Mynt is GDPR compliant, ensuring high standards of data protection, privacy, and security. We implement strict controls to safeguard personal data, provide transparency in data processing, and uphold individuals' rights under the General Data Protection Regulation (GDPR).

Code of conduct

Mynt has implemented a Code of Conduct that sets clear ethical principles and guidelines that all employees must follow, ensuring integrity, transparency, and accountability in everything we do. We also expect our suppliers and partners to uphold equivalent high standards, fostering a responsible and ethical business environment across all business areas.

Money security

Secure money handling is fundamental at Mynt.

Handling of money and deposit guarantee

As a licensed e-money institution, Mynt is obliged to protect customers' money. Mynt does this by keeping customers’ money in a segregated client funds account. By doing so, client funds are covered by the government deposit guarantee through the Swedish National Debt Office, up to 1 050 000 SEK per customer account (about 95 000 EUR)

Product security

Mynt’s product offers a broad range of security features to ensure security in customer access use and operation of the platform.

Strong customer authentication (SCA)

The Mynt platform implements strong customer authentication (SCA) to ensure secure and seamless access for our users while meeting PSD2 requirements. Strong authentication protects customer accounts against unauthorized access. By leveraging strong authentication technologies tailored to different regions, we enhance account security while maintaining a frictionless user experience.

Roll-based access control (RBAC)

The Mynt platform uses roll-based access control to guarantee that users can only access those resources that their role allows, following the principle of least privilege. Customer administrators can easily manage users and configure roles within the service.

Approval flows

Mynt allows administrators to configure approval flows for expenses and reimbursements. This ensures that only approved expenses are booked in the general ledger and, where relevant, paid out.

Software security

Mynt’s software has been developed from the ground up to prevent and protect against vulnerabilities.

Secure coding practices

Mynt platform is hosted on Amazon Web Services (AWS) cloud environment, with both storage and compute. Europe-west 1 (Ireland) is the primary infrastructure location. Infrastructure is configured using cloud formation and infrastructure as code. This enables rapid restore times should the network setup need to be restored.

Data encryption

Mynt system uses AES-256 encryption for data at rest, and https and TLS 1.2+ communication for encryption in transit. This ensures customer data is secure at every stage during storage, transit, and processing. Cryptographic keys, API tokens and other secrets are managed by AWS Secrets Manager and are only accessible by its corresponding sub-system

Vulnerability and patch management

Software source code and dependent libraries are scanned regularly for known vulnerabilities. In addition, all built deliverables are scanned for known operating system and application vulnerabilities. Patchers and updates are applied on a regular basis. Running application servers are monitored for unusual activity, such as new processes and unexpected network traffic.

Infrastructure security

Mynt takes pride in maintaining industry best-practice environment for hosting, network security, and infrastructure security.

Hosting & network

Mynt’s platform is hosted on Amazon Web Services (AWS) cloud environment, leveraging both storage and compute services. Ireland (eu-west-1) is the primary infrastructure location. Mynt’s infrastructure is managed as code (IaC) in order to provide consistent deployments, configuration and updates. This also ensures quick restore time if needed.

Network segmentation

Mynt’s platform operates within a hardened Virtual Private Cloud (VPC) in a dedicated AWS account, ensuring strict isolation and security. Our cloud infrastructure is designed with both vertically and horizontally segmented subnets, both isolating infrastructural layers as well as specific services from each other and allows communication only on a need-to-know basis. Outbound traffic is permitted through a Network Address Translation (NAT) service.

To enforce robust access controls, Mynt implements granular security groups and Network Access Control Lists (NACL) with service-specific rules. By default, all inbound traffic is denied with only explicitly allowlisted connections permitted. This zero-trust approach minimizes attack surfaces and strengthens our cloud security posture.

Intrusion detection and prevention systems (IDPS)

Mynt uses Upwind intrusion detection and prevention system to protect the cloud hosting and network infrastructure environment. Upwind continuously monitors network traffic and system activities, identifying and mitigating potential threats in real time. By using advanced anomaly detection and automated response mechanisms, Mynt proactively defends against unauthorized access, malware, and other security risks.

AI hosting

Mynt deploys AI capabilities within its dedicated cloud environment, ensuring all customer data remains exclusively within Mynt's secure AWS network infrastructure. This ensures that sensitive information never leaves Mynt's controlled environment and cannot be utilized for training or improving third-party commercial AI models.

Information security

Mynt has developed information security protocols to ensure adherence to best practices, leading to a strong information security environment.

Background checks & vetting

At Mynt, all new employees undergo rigorous background checks as part of the hiring process to verify identity and employment credentials. Additionally, we implement ongoing monitoring throughout employment, conducting periodic security assessments to maintain a secure and trusted workforce.

Security awareness

At Mynt, we recognize that information security is a collective responsibility that involves every department and employee. We foster a culture of security awareness, ensuring that all staff members contribute to maintaining high standards of confidentiality, integrity, and availability. To support this, employees receive regular, ongoing training on the latest information security principles, policies, and best practices, ensuring they remain informed and equipped to uphold our security commitments.

Access control

Internal accesses are provided on a least privileged basis, and resources configured on the principle of zero trust. Access controls are reviewed at regular intervals to ensure compliance with Mynt’s access management policies.

Data identification, separation and retention

We classify data based on sensitivity and criticality, ensuring appropriate handling and access controls for each data type. Sensitive data is isolated in secure environments, and strict separation protocols are enforced to limit exposure. Data retention is managed according to legal and regulatory requirements, with deletion or anonymization processes in place for data that is no longer required. These measures minimize risk, optimize data security, and ensure the responsible management of information throughout its lifecycle.

Penetration testing

Mynt conducts regular penetration tests to proactively identify vulnerabilities and ensure our platform and endpoints are securely configured to minimize the risk of intrusion. These tests are performed by certified professionals using the latest methodologies and industry standards. Penetration test summary report can be shared on request.

Business continuity & Incident management

Mynt has developed robust business continuity and incident management plans and procedures to ensure effective management of incidents.

Business continuity and disaster recovery

At Mynt, we follow industry best practices in Business Continuity and Disaster Recovery (BCDR) to ensure the resilience and security of our platform. Our robust strategy includes continuous data backups, redundancy in backups, and incident response plans to minimize disruptions and maintain service availability.

Through proactive risk assessments, monitoring systems that provide alerts, and regular reviews and testing, we ensure that our systems can quickly recover from unexpected events, keeping our customers’ data secure and our services reliable.  We invest in ongoing staff training to ensure our team is prepared to respond as incidents arise, maintaining seamless operations and protecting our customers' data.

Incident management

Mynt has implemented a robust and tested process for incident management, as a way of minimizing disruption and restoring services as effectively as possible. All employees receive regular training to ensure detection, reporting, and incident management processes are well known. The processes include steps for holistic communications with customers, partners, and regulators, and internal stakeholders, as relevant to the specific case.

Incident reporting

Are you aware of an ongoing incident? Please report this by contacting support@mynt.com or calling our support number +46 10 198 0300. When contacting us we appreciate it if you describe the incident as clearly and comprehensively as possible.

Financial crime prevention

Mynt takes its role in financial crime prevention seriously by implementing industry best practices across several areas.

Know Your Customer

As a regulated e-money institution (EMI), Mynt has a requirement to have knowledge about our customers and their businesses. This means we carry out a Know Your Customer (KYC) process before we do business with any customer, and renew this at regular intervals. We ask our customers to complete a KYC questionnaire, and we may require customers to submit additional data and documentation. Our identity verification processes and adaptive risk assessments ensure compliance with global regulations while minimizing friction for legitimate businesses.

Transaction & fraud monitoring

To detect potential financial crime, either done to our customers or by our customers, we monitor transactions 24/7 in accordance with best practices. We monitor for anomalous or suspicious transactions, and transactions that fall outside the scope of what we would expect based on our customer’s profile. We may reach out to customers to understand certain transactions, and in some cases we may need to suspend transactions and/or services until we have gained a better understanding.

Audit & oversight

In line with requirements and best practices, we have three lines of defense in maintaining our risk and compliance posture. We work closely with the Swedish Financial Supervisory Authority (Finansinspektionen) to ensure full compliance and maintenance of our e-money license. Finally, we collaborate closely with other relevant authorities, including the Swedish financial police, to proactively prevent financial crime and uphold the security of the financial ecosystem.

Subprocessors

Mynt collaborates with a number of subprocessors in delivering the services.

Amazon Web Services EMEA SARL
Creditsafe i Sverige AB
Criipto ApS
Enfuce Financial Services Ltd
Enable Banking Oy
IDEMIA Sweden AB
Intercom, Inc

Request documents

Request security related documentation

What documents are you interested in?
Thank you for your request, we'll be in touch soon
Oops! Something went wrong while submitting the form.