Sorbet Logo Sorbet
🛡️ Sorbet Security & Compliance

Bank‑grade protection for your Estonian company’s finances

Sorbet connects to your banks using regulated Open Banking APIs, encrypts your data end‑to‑end, and is operated under an ISO 27001‑certified information security management system.

Founders get one cockpit. Accountants get perfect data. Everyone gets serious security.

✅ ISO 27001‑certified information security 🔗 PSD2/Open Banking AIS & PIS connections 🇪🇺 EU data residency

At a glance

  • 🔒

    Encryption everywhere

    All connections use TLS. Data at rest is encrypted using strong, industry‑standard algorithms.

  • 🧾

    Full audit trails

    Key actions—like payments, exports and configuration changes—are logged with who, what and when.

  • 📍

    Data stays in the EU

    Sorbet runs on EU‑based infrastructure, aligned with GDPR and European data protection expectations.

  • 🧊

    We never touch your funds

    Payments are executed directly by your bank or fintech via PIS. Sorbet orchestrates, but doesn’t hold client money.

ISO 27001‑certified information security

Sorbet operates under an ISO 27001‑certified information security management system (ISMS).

ISO 27001 is the international standard for managing information security. Certification means that an independent auditor has verified that we:

  • • Maintain a formal security management system with documented policies and controls
  • • Assess and treat risks to customer data on an ongoing basis
  • • Implement technical, organisational and physical safeguards
  • • Regularly review, test and improve our security posture

What ISO 27001 means for you

  • • Your bank and accounting data is handled under a recognised security framework.
  • • There is a clear process for access management, incident response, and change control.
  • • Security isn’t an afterthought or a slide in a pitch deck—it’s baked into how we operate Sorbet.

If you are an accountant or larger SME and need details for your own risk assessment, reach out via Contact.

How Sorbet connects to your banks and wallets

We use regulated Open Banking (PSD2) connections for AIS (account information) and PIS (payment initiation). You authenticate directly with your bank; Sorbet never learns your online banking password.

🔗 AIS — Account Information Services

AIS lets Sorbet read balances and transactions from your banks and fintech providers.

  • • Read‑only access to account data
  • • No ability to move funds
  • • Scope & consent controlled by you

💸 PIS — Payment Initiation Services

PIS lets Sorbet prepare payments that your bank executes, with your strong customer authentication.

  • • You approve each payment with your bank’s SCA (e.g. app, token)
  • • Sorbet never holds or re‑routes your funds
  • • You see all payments inside your normal bank environment

🧊 No passwords, no scraping

Sorbet does not ask for your online banking credentials or scrape websites.

  • • You authenticate directly with your bank
  • • Access tokens are stored securely and can be revoked
  • • Connections follow bank and regulator expectations

How we protect your data inside Sorbet

We treat your company’s financial data like production code in a mission‑critical system: locked down, monitored and change‑controlled.

Encryption in transit & at rest

All communication between your browser, our APIs, and banking partners is protected with TLS.

  • • Transport encryption (HTTPS/TLS) for all external connections
  • • Data at rest encrypted using industry‑standard algorithms
  • • Encrypted backups with strict access controls

Access control & least privilege

We follow a least‑privilege model inside Sorbet.

  • • Role‑based access inside our systems
  • • Restricted access to production data, with logging
  • • Separation between environments (development, staging, production)

Monitoring, logging & audit trails

We log security‑relevant events and maintain audit trails around key actions.

  • • Application and infrastructure logging
  • • Audit logs around payments, exports and configuration changes
  • • Alerts for suspicious behaviours and failed access attempts

Backups & business continuity

We maintain regular backups and a documented incident response process.

  • • Regular backups of key data stores
  • • Tested restore procedures
  • • Incident response and escalation playbooks as part of our ISMS

🍦 For founders

You want one cockpit, not another attack surface.

  • • Sorbet sits on top of banks you already trust—LHV, Wise, Revolut, etc.
  • • You can revoke access to any connection at any time.
  • • We never move funds without your explicit bank‑level approval.

📚 For accountants & finance teams

You need security evidence for your own risk assessment and for auditors.

  • • ISO 27001‑certified ISMS in place.
  • • Clear segregation of duties between Sorbet, banks and accounting systems.
  • • Exportable audit trails you can keep with your workpapers.

Need more detail for your internal documentation? Contact us and we’ll share the necessary information under NDA where appropriate.

Security questions we hear most often

If you’re an e‑resident founder or an accountant, you should ask these questions. Here are our answers.

Is Sorbet a bank or licensed to hold client funds?

No. Sorbet is a Finance OS that connects to your existing banks and fintechs via regulated APIs. Your money always sits with your bank or payment provider. Sorbet orchestrates, but never becomes the holder of your funds.

Do you see my online banking password or card details?

No. You authenticate directly with your bank or fintech using their own login and strong customer authentication. Sorbet receives an access token with limited scope, not your password or card number.

Can I revoke Sorbet’s access to my accounts?

Yes. You can disconnect a bank or wallet from inside Sorbet, and you can revoke consent from your bank or provider directly. Once revoked, Sorbet cannot fetch new data or initiate payments for that account.

Where is my data stored?

Sorbet runs on EU‑based infrastructure. We prioritise EU data residency and follow GDPR principles. If you need precise details for a DPIA or internal review, contact us and we will provide them.

Who inside Sorbet can see my data?

Access to production systems is strictly limited to specific roles and is logged. Day‑to‑day operations are designed so that most support interactions can be handled without viewing sensitive data unless absolutely necessary.

Is this page legal advice or a contract?

No. This page is an overview of how we approach security and compliance. For binding terms, please refer to our Terms of Service and Privacy Policy, and to any specific agreements we sign with you.