What is open banking?

Banks and other financial institutions allow regulated service providers to access, use and share bank data - this is the foundation of open banking, which is not designed to make it easy for banks to sell their customers' data.

On the contrary, the goal of open banking is to improve financial services for customers. By opening up access to data that has traditionally been kept within banks, new companies and products can enter the market and use that data in useful and innovative ways.

Ensuring security in open banking is extremely important, and banks are setting up an infrastructure that enables a more secure exchange of data with third parties. It is important to emphasize that data exchange takes place only with the user's approval.

How does open banking work?

Technically, open banking is based on APIs (application programming interface). An API is simply a structured way for one program to offer services to another program, or in simpler terms, it's a way for software to communicate with other software. For open banking, APIs provide instructions on how third parties can access bank data.

After APIs are agreed upon by all participants in the open banking initiative (eg governments, regulators and banks), banks are responsible for their creation, implementation and maintenance. Companies can then start accessing these APIs and develop new, innovative products based on them. The users of these companies — whether they are consumers, small businesses or large corporations — can ultimately profit from using these innovative solutions.

The FIRA application successfully integrates more than 2,300 banks and payment service providers from 30 European countries.

  • Belgium
  • Greece
  • Portugal
  • Latvia
  • Italy
  • Iceland
  • Poland
  • Czech-Republic
  • Liechtenstein
  • Finland
  • United-Kingdom
  • Bulgaria
  • Netherlands
  • Ireland
  • Sweden
  • Estonia
  • Slovenia
  • Denmark
  • Austria
  • Luxembourg
  • Norway
  • Germany
  • Slovakia
  • Cyprus
  • France
  • Croatia
  • Romania
  • Malta
  • Spain
  • Hungary
  • Lithuania

What is PSD2?

The PSD2 (Payment Service Directive) directive of the European Union made it possible for you, as the owner of your bank data, to manage and use it for any purpose. In our case, PSD2 is used so that FIRA can display traffic and account balances and, for example, automatically compare payments with issued invoices.

PSD2 integrator

Our business partner for open banking is GoCardless, which according to the PSD2 directive is a licensed account information service provider, i.e. AISP (Account Information Service Provider) for the EEA (European Economic Area). GoCardless is authorized by the French National Bank - ACPR (French regulator for prudential supervision and rehabilitation).

Security

Servers and network

FIRA is a cloud application, built on secure cloud solutions and infrastructure provided by Microsoft Azure which is located in the European Union.

The development of FIRA utilizes 24-hour monitoring, extensive logging services, and a gradual software implementation process to ensure the stable operation of FIRA services. We have emergency procedures in place to deal with service disruptions and any external attacks.

Data protection

FIRA encrypts your confidential data using industry-leading methods and recognized security standards (256-bit SSL certificates), so that all data transmitted between your computer and our servers, or individual services on our servers, always remains encrypted.

FIRA's cloud infrastructure runs on servers located in the European Union and is therefore subject to the strict privacy regulations set out in the European Commission Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data.

Passwords and application security

FIRA never stores passwords in plain text format in its databases. Instead, it uses mathematical algorithms to manage data to ensure that your password is securely encrypted and difficult enough to hack.

Security of credit card payments

The confidentiality of your data is protected and ensured by the use of SSL encryption. Online payment pages are secured using the Secure Socket Layer (SSL) protocol with 128-bit data encryption.

SSL encryption is the process of encrypting data to prevent unauthorized access during its transmission. This enables safe transfer of information and prevents unauthorized access to data during communication between the user's computer and the WebPay service, and vice versa. The WebPay service and financial institutions exchange data using a virtual private network (VPN), which is protected against unauthorized access.

Monri Payment Gateway is certified according to PCI DSS Level 1 security standard prescribed by Visa and Mastercard rules. FIRA does not store credit card numbers.