Neumetria has been certified to ISO/IEC 27001. Scope: the Neumetria platform and its production cloud infrastructure.
Why it matters
Neumetria runs on behavioral financial data — income rhythm, liquidity horizon, debt service — the inputs banks use to assess thin-file and gig-worker credit. ISO 27001 is third-party proof that the infrastructure handling it is secure, not a claim we're making ourselves.
What it means for Neumetria
ISO 27001 isn't a one-time badge — it's an ongoing management system: risk assessment, access control, incident response, and vendor oversight, reviewed and re-audited on a fixed cycle. Getting certified means those practices, which we already run internally, are now documented, tested, and checked by someone outside the company. It also removes a gate we'd otherwise hit repeatedly: several of the banks and enterprise partners we talk to won't sign without it.
What it means for our customers
For the institutions integrating Neumetria — including partners within the Mastercard Lighthouse FINITIV program — this shortens vendor security review from a multi-week questionnaire process to pointing at a certificate. It also gives their own compliance and risk teams something concrete to cite when they're accountable for third-party data handling under their own regulatory obligations. Nothing about the product changes: institutions keep policy authority, decisions stay reversible, human override stays in place. What's new is that the security behind it no longer has to be taken on our word.
“ISO 27001 doesn't change what we do — we still just execute the policy the bank sets, and every decision stays reversible on their end. What it changes is who has to trust us to get there. Before, a bank's security team would ask us for documentation and take our word on how we handle their data. Now there's a certificate behind it, audited every year, and it's not us saying it's secure.”
— Amr Mohamed, CEO, Neumetria
by Amr Mohamed