Security
Security
Swiss Fiat AG is a Swiss financial intermediary. Protecting client information is a regulatory obligation, an operational discipline, and an independently audited part of how we run the business.
ISO/IEC 27001:2022 certification
Swiss Fiat AG is certified to ISO/IEC 27001:2022, the international standard for information security management systems.
Registration number: IC-IS-2609188
Standard: ISO/IEC 27001:2022
Initial certification: 17 September 2026
Valid until: 16 September 2027, maintained through annual surveillance audits
Recertification: 16 September 2029
Scope of certification
The Information Security Management System at Swiss Fiat AG applies to the provision of multi-currency accounts, dedicated IBANs, payment cards, foreign exchange, and digital asset on and off ramp services to individual and business clients, including the supporting departments and functions: Executive and Governance, Compliance and AML, Technology and IT, Operations and Payments, Finance and Administration, and Marketing and Business Development.
What the certification covers
Independent audit confirmed that Swiss Fiat AG has established, documented and implemented controls across:
Access management. Role-based access, multi-factor authentication, privileged access controls, and quarterly access reviews. Accounts are provisioned only on approval and disabled when no longer required.
Encryption. Data encrypted at rest and in transit. Full disk encryption and anti-malware enforced on all endpoint devices.
Incident response. Documented processes for identifying, assessing, responding to and learning from information security events, with defined roles and reporting channels.
Business continuity. Continuity and disaster recovery plans with tested backups and recovery procedures.
Secure development. Security requirements built into the development lifecycle, with peer code review, security testing before production deployment, and separation of development, test and production environments.
Vendor and cloud risk. Formal vendor risk assessments and security requirements applied to suppliers and cloud services across the technology supply chain.
Monitoring. Continuous vulnerability identification, capacity and systems monitoring, and logging of security-relevant events.
Data protection. Documented data classification, retention, deletion and breach notification procedures.
Governance
Information security at Swiss Fiat AG is owned at board level. Our Chief Technology Officer serves as Information Security Officer, reporting directly to the CEO, with overall responsibility for establishing, operating, monitoring and improving the Information Security Management System. The system is reviewed by management at planned intervals and audited internally on a recurring schedule.
Privacy
Swiss Fiat AG handles personal data in line with GDPR principles. Data is collected for a defined purpose, held only as long as it is needed, and remains under the control of the person it belongs to. See our Privacy Policy for full details.
Regulatory standing
Swiss Fiat AG is affiliated with SO-FIT, Organisme de Surveillance pour Intermédiaires Financiers & Trustees, affiliation number 1524, as a financial intermediary under the Swiss Anti-Money Laundering Act. SO-FIT is recognised by the Swiss Financial Market Supervisory Authority (FINMA). See Supervision for more.
How we contact you
Swiss Fiat will never make unsolicited calls, request sensitive information, or ask you to transfer funds. If you receive a call claiming to be from Swiss Fiat, our in-app fraud call protection will indicate whether we are genuinely on a call with you.
If you believe you have been contacted by someone impersonating Swiss Fiat, or you want to report a security concern, email support@swissfiat.com