Educational use only. Not financial, investment, tax or legal advice.

Delphina Security

We take data security seriously. Your financial information deserves vault-grade protection, so the entire platform is designed with privacy, encryption and safe account access at its core.

30 May 2026

How we protect your data

Bank-Grade Encryption

Data is encrypted in transit (TLS 1.2+) and at rest using industry-standard AES-256

Secure Authentication

Personal and financial information protected behind multiple security layers

No Credential Storage

We never store your banking credentials - only secure access tokens

Vetted Partners

All third-party services undergo rigorous security vetting

Data Hosting

Your data is hosted in secure, GDPR-compliant data centers within the European Union to ensure maximum privacy and data protection.

AWS

Dublin (eu-west-1)

Primary database hosting with ISO 27001, SOC 2 Type II, and GDPR compliance certifications.

Hetzner

Nuremberg (eu-central)

Primary application hosting with ISO 27001 certification and EU data protection compliance.

EU Data Residency: All your personal and financial data remains within the European Union, complying with GDPR requirements and ensuring maximum privacy protection.

Regulator oversight of underlying infrastructure:Delphina’s infrastructure runs on cloud providers that are now directly overseen by the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority as Critical Third Parties under the regime that came into force on 13/07/2026. This is operational resilience oversight of those providers’ services to UK financial firms, and sits alongside our existing ISO 27001, SOC 2 Type II and UK GDPR obligations. It is not FCA authorisation of Delphina, and it does not affect your data protection rights under UK GDPR or the Data Protection Act 2018.

Bank-level access & no-touch transfers

Delphina connects using regulated Open Banking providers. You can see your accounts and transactions, but we can't move your money or make any changes to your accounts. Read-only, always in your control.

Compliance & standards

Regulatory Compliance

  • UK Open Banking compliant
  • GDPR aligned data handling and retention
  • ICO registered (ZC069960) - View registration

Security Practices

  • Regular penetration tests and vulnerability scanning
  • Clear audit trails and access logs

Your privacy

You own your data. We only use it to provide features within Delphina, never to sell to third parties. You can export or delete your data at any time from your account settings.

Incident response

If something feels off, we're prepared. We maintain a tested incident response plan, continuous monitoring and rapid resolution pathways.

Have security concerns?

Contact support