Remitly Cybersecurity Policy Summary


Introduction
At Remitly, safeguarding the information and data provided to us by customers and personnel is paramount and is embedded in our corporate values. We actively protect our systems, networks, and data from unauthorized access, use, disclosure, disruption, modification, or destruction. This policy outlines the core principles and guidelines that ensure strong cybersecurity across our organization.

Security Measures
  • Access Control: Only authorized personnel can access critical systems and data. Strong, unique passwords with regular changes are mandatory. Multi-factor authentication (MFA) safeguards access to sensitive information.
  • Data Protection: Encryption safeguards sensitive data both in transit and at rest. Critical data is regularly backed up and securely stored. We handle all data which we are responsible for in strict compliance with all applicable data protection regulations.
  • Network Security: Defenses in depth including intrusion detection systems shield Remitly's networks. Regular vulnerability assessments and penetration tests identify and address weaknesses. Network access is monitored and controlled to prevent unauthorized activity. Public bug bounties are posted to incentivize researchers and others to help us

Incident Response
We maintain and test well-defined incident response plan that is updated regularly as systems change and the threat landscape shifts. All employees are trained to identify and report security incidents promptly.


Employee Awareness and Training
Regular cybersecurity training is provided to all personnel who access Remitly systems, including responsible password hygiene, safe browsing habits, and awareness of phishing and social engineering tactics.


Third-Party Vendors
Third-party vendors with access to our systems or data must comply with our cybersecurity standards at minimum. Remitly maintains confidentiality agreements and security equivalence agreements with all vendors and partners, including regular risk assessment and reviews of their certifications or security and privacy programs.