Sumeria can be used safely as your main account
Banking services are operated by Lydia Solutions, a French electronic money institution authorized and supervised by the Autorité de contrôle prudentiel et de résolution (ACPR) of the Banque de France. Your money, your account, your payments, and your data are protected by several independent safeguards, and the company is supervised to guarantee this level of security.
Our solutions are designed, developed, and monitored in France, 24/7, by our own cybersecurity experts. Beyond the ACPR, our activity is also supervised by the CNIL for the protection of your personal data, and relies on ANSSI standards for digital security.
This page explains these protections and answers the main questions about Sumeria’s security.
The “Vauban System”: defense in depth, layer by layer
For centuries, the best way to prevent attacks has been to stack several layers of security, so that if one fails or is bypassed, the others remain in place.
Account security should never depend on a single factor, such as a password, or on a single system. Sumeria combines several levels of protection to prevent an attack, detect it, and reduce its impact as much as possible.
Communications and sensitive data are encrypted or anonymized. Systems are compartmentalized, and internal access is limited according to the principle of least privilege. Security events are monitored 24/7 by Lydia Solutions’ cyber teams, as well as by our independent French partner Intrinsec. The infrastructure and applications are regularly subject to vulnerability scans and penetration tests, both internally and by independent providers certified by ANSSI.
The mobile app also has its own protections. It can detect certain compromised, rooted, or jailbroken devices, as well as attempts to modify or maliciously analyze the app (application shielding and Runtime Application Self-Protection). This shielding is provided by Promon, a leading European mobile application security company: your app remains protected against malicious modifications, including if your phone is lost or stolen.
These safeguards are part of the requirements that apply to the financial sector, including PCI DSS, DORA, and the GDPR.
Your phone as a security key
To protect you as much as possible and prevent identity theft, we link your account to a trusted device.
A Sumeria account can only be used on one mobile device at a time. When a new phone is registered, the old one can no longer access the account.
This trusted device is also used to secure the web app. A login from a computer must be authorized from the mobile app: knowing the password is therefore not enough to take control of the account.
Sumeria checks several elements depending on the level of risk of the actions being performed: the device used, the password, the security code, biometrics, or the customer’s identity. An additional check may be requested in the event of an unusual login to ensure that only you can access your account.
Where possible, we also use what is known as silent authentication, which makes it possible to confirm directly with the mobile operator that the phone number is in your possession. No SMS code then needs to be copied or shared, which strengthens security.
Finally, several incorrect access attempts trigger the automatic blocking of the account. The app remains unusable until our customer service team intervenes and contacts you to secure your access.
A product secured by design (security by design)
Sumeria does not only seek to detect fraud or attempts to take over your account. The product is designed to limit the information and features that a fraudster or hacker could exploit.
For example, for a one-off purchase on a website you do not know, Sumeria will recommend using a single-use virtual card, automatically destroyed after payment: the merchant then keeps no data that could later be stolen and used.
Similarly, if you need to share bank details to receive money but are concerned about how they might be used, you can use a “one-way” IBAN, which can only receive money: any direct debit submitted on this IBAN is automatically rejected.
In addition, without you even noticing, your Sumeria app also checks that the beneficiary’s name matches the actual holder of the IBAN you entered, to help prevent transfers from being diverted to a fake beneficiary.
Each card also remains fully controllable: you can enable or disable, on demand and individually, online payments, ATM withdrawals, contactless payments, and use abroad at any time. Spending limits can be changed instantly, and a card that has not been used for six months is automatically suspended; this means that even if you forget about it or lose it, your money remains protected.
The principle is simple: temporary data, limited use, or a disabled feature gives a fraudster fewer opportunities. If in doubt, you can personalize the options for all your cards whenever you like.
Payments and data reduced to what is strictly necessary
The less information circulates, the less it can be stolen. Sumeria applies this principle to your payments as well as to your data.
The data associated with your transactions is pseudonymized or tokenized and timestamped, and its integrity is verified using tokens that only our systems can produce and interpret. These tokens contain no banking or personal information, are unique, cannot be replayed, falsified, or modified, and have a limited lifespan.
Finally, your personal and banking data is limited to what is strictly necessary, and is encrypted and/or anonymized at every stage of processing. Our technical teams, who may sometimes work on sensitive cases, only see masked information with no identifying data.
Checking that Sumeria really is Sumeria
Fraudsters do not always try to attack IT systems. They may pretend to be an advisor in order to convince the victim to approve a transaction themselves.
Sumeria therefore also secures the relationship with its teams. Calls and messages from our advisors only go through the mobile app, which guarantees the origin of the communication.
Thanks to our free Call Shields feature, if the app detects that you are on a phone call during a transaction, an on-screen indicator lets you confirm whether the person you are speaking to is really a Sumeria advisor. If in doubt, hang up and contact us again from the app.
An advisor will never ask for a password, a security code, a card PIN, or a card security code. They will also never ask you to transfer money to a so-called “secure account.”
Silent authentication, in-app calls, Call Shields, and fake advisor detection are among the protections currently offered by very few banking players in France.
Your money remains protected
Sumeria is operated by Lydia Solutions, a French electronic money institution authorized and supervised by the ACPR, under bank code 17598 and REGAFI identifier 62677.
Customer funds are segregated from Lydia Solutions’ own funds. They cannot be used to finance the company or grant loans, and remain protected from claims by its other creditors.
In accordance with Article L. 526-32 of the French Monetary and Financial Code, these funds are deposited in a safeguarding account opened with a credit institution established in the European Economic Area, or are occasionally invested in eligible short-term money market funds. This protection applies even in the event of enforcement proceedings or insolvency proceedings involving Lydia Solutions.
If the banking institution where the funds are deposited fails, deposits are covered by the Fonds de garantie des dépôts et de résolution up to €100,000 per customer and per institution.
Money is not stored on the phone. If your phone is lost or stolen, the account remains intact and access can be transferred to a new device after the customer’s identity has been verified.
We keep watch, even when you are not using the app
Security events are monitored 24/7 by Lydia Solutions’ dedicated teams and by our French partner Intrinsec, which is certified by ANSSI.
This monitoring extends beyond our systems: we continuously monitor cards and accounts offered for sale by fraudsters on the dark web.
In practical terms, we aim to detect and block intrusion attempts and fraudulent transactions as early as possible. If a risk is identified, we notify you quickly, secure your account, and support you in recovering access.
This monitoring combines the expertise of our teams with the most advanced technologies, including artificial intelligence and automated vulnerability scans. The results are analyzed by our experts to identify, prioritize, and fix vulnerabilities, detect abnormal behavior and new threats, and continuously adapt our protections.
A service that remains available
An outage should never deprive you of your money. Our systems are designed to continue operating even if a component fails.
Data is replicated and backed up regularly on redundant infrastructure. Backups are subject to restore tests.
We maintain a business continuity and disaster recovery plan, tested periodically, as well as a crisis organization that can be mobilized at any time. In the event of a major incident, you are informed in the app and your funds remain intact, whatever the circumstances.
These safeguards meet the requirements of the European DORA regulation on the operational resilience of the financial sector.
Our requirements also apply to our partners
Each partner is assessed before any commitment is made: resilience, security practices, certifications, and data location. Our security requirements are included in contracts.
This assessment then continues over time: periodic reassessments proportionate to the criticality of the service, monitoring of incidents and vulnerabilities, review of audit reports and certifications, and monitoring of risk signals. A provider that no longer meets our requirements is placed under an action plan or replaced.
This third-party risk management meets the requirements of the European DORA regulation on operational resilience and the control of critical service providers.
Act immediately if in doubt
You remain in control of your payment methods at all times. You can block your account or a card, disable a feature, and change your spending limits directly from Sumeria.
If you no longer have access to the app, you can request that your card be blocked 24/7 from the login screen.
Sumeria therefore combines IT security, strong authentication, and direct control: advanced protections designed to remain simple to use.