ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Scalable Capital is a leading FinTech in Europe, bringing people and technology-based investment together. The company was founded in 2014 and has offices in Munich, Berlin and London. For private individuals, Scalable Capital offers a broker with a trading flat rate and interest and a digital wealth management. In digital wealth management, the company creates and manages globally diversified ETF portfolios for its clients with sustainable investment strategies when desired. The broker enables private individuals to trade stocks, ETFs, crypto, funds and more with as little as €1 and to set up ETF and stock savings plans with as little as €1. As a fast-growing FinTech, we are constantly looking for new employees and also welcome unsolicited applications: https://careers.scalable.capital/ For further information please visit our website: www.scalable.capital. Scalable Capital refers to Scalable GmbH and the affiliated companies. If this online presence contains information regarding capital markets, financial instruments and/or other topics relevant for investments of assets, the exclusive purpose of this information is to give general guidance on the investment services provided by Scalable Capital Limited and Scalable Capital GmbH. Our Privacy Policy can be found here: www.scalable.capital/privacy-policy

Scalable Capital A.I CyberSecurity Scoring

Scalable Capital

Company Details

Linkedin ID:

scalable-capital

Employees number:

581

Number of followers:

56,133

NAICS:

52

Industry Type:

Financial Services

Homepage:

scalable.capital

IP Addresses:

0

Company ID:

SCA_2498266

Scan Status:

In-progress

AI scoreScalable Capital Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/scalable-capital.jpeg
Scalable Capital Financial Services
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreScalable Capital Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/scalable-capital.jpeg
Scalable Capital Financial Services
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Scalable Capital Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Scalable CapitalBreach100410/2020
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: A data protection breach at Scalable Capital resulted in the theft of sensitive information, including the identification, tax, and account information of about 20,000 clients. A letter that stated there had been an unauthorized access to private client information in its document archive was used to notify the impacted clients of the issue. The company claimed that during the incident, access was made to contact information, securities accounts, tax identity numbers, accounts with other banks, and ID details. Since there is no externally exploitable security hole in its system, the robo-adviser believes the leak was caused by extensive insider knowledge.

Scalable Capital
Breach
Severity: 100
Impact: 4
Seen: 10/2020
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: A data protection breach at Scalable Capital resulted in the theft of sensitive information, including the identification, tax, and account information of about 20,000 clients. A letter that stated there had been an unauthorized access to private client information in its document archive was used to notify the impacted clients of the issue. The company claimed that during the incident, access was made to contact information, securities accounts, tax identity numbers, accounts with other banks, and ID details. Since there is no externally exploitable security hole in its system, the robo-adviser believes the leak was caused by extensive insider knowledge.

Ailogo

Scalable Capital Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Scalable Capital

Incidents vs Financial Services Industry Average (This Year)

No incidents recorded for Scalable Capital in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Scalable Capital in 2025.

Incident Types Scalable Capital vs Financial Services Industry Avg (This Year)

No incidents recorded for Scalable Capital in 2025.

Incident History — Scalable Capital (X = Date, Y = Severity)

Scalable Capital cyber incidents detection timeline including parent company and subsidiaries

Scalable Capital Company Subsidiaries

SubsidiaryImage

Scalable Capital is a leading FinTech in Europe, bringing people and technology-based investment together. The company was founded in 2014 and has offices in Munich, Berlin and London. For private individuals, Scalable Capital offers a broker with a trading flat rate and interest and a digital wealth management. In digital wealth management, the company creates and manages globally diversified ETF portfolios for its clients with sustainable investment strategies when desired. The broker enables private individuals to trade stocks, ETFs, crypto, funds and more with as little as €1 and to set up ETF and stock savings plans with as little as €1. As a fast-growing FinTech, we are constantly looking for new employees and also welcome unsolicited applications: https://careers.scalable.capital/ For further information please visit our website: www.scalable.capital. Scalable Capital refers to Scalable GmbH and the affiliated companies. If this online presence contains information regarding capital markets, financial instruments and/or other topics relevant for investments of assets, the exclusive purpose of this information is to give general guidance on the investment services provided by Scalable Capital Limited and Scalable Capital GmbH. Our Privacy Policy can be found here: www.scalable.capital/privacy-policy

Loading...
similarCompanies

Scalable Capital Similar Companies

Barclays Investment Bank

Barclays Investment Bank deploys financial solutions to help our clients with their funding, financing, strategic and risk management needs across sectors, markets and economies. The Investment Bank is comprised of the Investment Banking, International Corporate Banking, Global Markets and Researc

Motilal Oswal Financial Services Ltd

Motilal Oswal Financial Services Ltd. (MOFSL) was founded in 1987 as a small sub-broking unit, with just 2 people running the show. Focus on a customer-first attitude, ethical and transparent business practices, respect for professionalism, research-based value investing, and implementation of cutti

SM Investments

SM Investments Corporation is a leading Philippine company that is invested in market-leading businesses in retail, banking, and property. It also invests in ventures that capture high growth opportunities in the emerging Philippine economy. SM’s retail operations are the country’s largest and most

Discover

Discover® is now part of Capital One. Together, we’ll continue to deliver exceptional financial products and experiences, drive innovation, and serve customers. Find the latest updates at https://capitalonediscover.com. Discover is one of the most recognized brands in the U.S. with the Discover® ca

Paytm

Paytm started the Digital Revolution in India. And we went on to become India’s leading Payments App. Today, more than 20 Million merchants & businesses are powered by Paytm to Accept Payments digitally. This is because more than 300 million Indians use Paytm to Pay at their stores. And that’s not

KPMG US

KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. With 75+ offices and more than 40,000 employees and partners throughout the US, we’re leading the industry in new and exciting ways. Our size and strength make us muc

Citi's mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress. Our core activities are safeguarding assets, lending money, making payments and accessing the capital markets on behalf of our clients. We have over 20

Equifax

At Equifax (NYSE: EFX), we believe knowledge drives progress. As a global data, analytics, and technology company, we play an essential role in the global economy by helping financial institutions, companies, employers, and government agencies make critical decisions with greater confidence. Our uni

CIMB Group is a leading ASEAN universal bank, one of the largest Asian investment banks and one of the world's largest Islamic banks. We are headquartered in Kuala Lumpur, Malaysia and offer consumer banking, commercial banking, wholesale banking, Islamic banking, and asset management products and

newsone

Scalable Capital CyberSecurity News

December 10, 2025 03:20 PM
OCIO announces scalable cybersecurity services for schools, nonprofits

88 words | Data & Security, Policy & Funding | Office of the Chief Information Officer, cybersecurity. The Department of Management Office of the Chief...

December 03, 2025 08:00 AM
Unicorn startups in Germany (Dec, 2025)

Discover all unicorn startups from Germany as of December 2025, with insights on valuations, funding, top investors, sectors,...

September 23, 2025 07:00 AM
Cyberbit Acquires RangeForce to Forge AI-Powered Operational Cyber Readiness for Businesses and Governments Worldwide

BOSTON--(BUSINESS WIRE)--Cyberbit, a leader in hyper-realistic attack simulation cyber ranges and SOC (Security Operations Center) readiness...

September 17, 2025 07:00 AM
RaiseLaw and Tribevest Drive Scalable Capital Strategies Under Seth Bradley's Legal Leadership

The San Diego based attorney brings legal structure and operational clarity to emerging investment professionals SAN DIEGO,...

September 03, 2025 07:00 AM
Cybersecurity Venture Capital Surges in Q2 2025, Supported by AI-Driven Demand : Research

According to the latest Cybersecurity VC Trends report from PitchBook, the industry saw $4 billion invested across 163 transactions.

August 28, 2025 07:00 AM
Q2 2025 Cybersecurity VC Trends

The Q2 2025 Cybersecurity VC Trends report provides an analysis of recent VC activity and includes a market map of leading VC-backed...

August 19, 2025 09:59 AM
Continuous protection

Capgemini's Continuous Protection services secure data, infrastructure, and users across IT, OT, and cloud—ensuring future-ready, scalable defense.

July 31, 2025 07:00 AM
Cynomi Launches ELEVATE Partner Program to Accelerate MSP and MSSP Growth with Scalable Cybersecurity Services

Cynomi, the AI-powered vCISO platform trusted by over 300 service providers, has launched the ELEVATE Partner Program to help MSPs and MSSPs...

July 31, 2025 07:00 AM
Ex-big tech cyber leaders launch Dawnguard from stealth with $3M to rewrite DNA of cybersecurity

Former IBM, Microsoft, Amazon and military cybersecurity leaders have combined to introduce a new cyber category — embedding various AI/ML...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Scalable Capital CyberSecurity History Information

Official Website of Scalable Capital

The official website of Scalable Capital is http://www.scalable.capital.

Scalable Capital’s AI-Generated Cybersecurity Score

According to Rankiteo, Scalable Capital’s AI-generated cybersecurity score is 732, reflecting their Moderate security posture.

How many security badges does Scalable Capital’ have ?

According to Rankiteo, Scalable Capital currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Scalable Capital have SOC 2 Type 1 certification ?

According to Rankiteo, Scalable Capital is not certified under SOC 2 Type 1.

Does Scalable Capital have SOC 2 Type 2 certification ?

According to Rankiteo, Scalable Capital does not hold a SOC 2 Type 2 certification.

Does Scalable Capital comply with GDPR ?

According to Rankiteo, Scalable Capital is not listed as GDPR compliant.

Does Scalable Capital have PCI DSS certification ?

According to Rankiteo, Scalable Capital does not currently maintain PCI DSS compliance.

Does Scalable Capital comply with HIPAA ?

According to Rankiteo, Scalable Capital is not compliant with HIPAA regulations.

Does Scalable Capital have ISO 27001 certification ?

According to Rankiteo,Scalable Capital is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Scalable Capital

Scalable Capital operates primarily in the Financial Services industry.

Number of Employees at Scalable Capital

Scalable Capital employs approximately 581 people worldwide.

Subsidiaries Owned by Scalable Capital

Scalable Capital presently has no subsidiaries across any sectors.

Scalable Capital’s LinkedIn Followers

Scalable Capital’s official LinkedIn profile has approximately 56,133 followers.

NAICS Classification of Scalable Capital

Scalable Capital is classified under the NAICS code 52, which corresponds to Finance and Insurance.

Scalable Capital’s Presence on Crunchbase

Yes, Scalable Capital has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/scalable-capital.

Scalable Capital’s Presence on LinkedIn

Yes, Scalable Capital maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/scalable-capital.

Cybersecurity Incidents Involving Scalable Capital

As of December 20, 2025, Rankiteo reports that Scalable Capital has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Scalable Capital has an estimated 30,672 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Scalable Capital ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does Scalable Capital detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with notified affected clients via letter..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Data Protection Breach at Scalable Capital

Description: A data protection breach at Scalable Capital resulted in the theft of sensitive information, including the identification, tax, and account information of about 20,000 clients. Affected clients were notified via a letter stating there had been unauthorized access to private client information in its document archive. The company claims that access was made to contact information, securities accounts, tax identity numbers, accounts with other banks, and ID details. The robo-adviser believes the leak was caused by extensive insider knowledge.

Type: Data Breach

Attack Vector: Insider Threat

Threat Actor: Insider

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach SCA0408523

Data Compromised: Identification information, Tax information, Account information, Contact information, Securities accounts, Tax identity numbers, Accounts with other banks, Id details

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Identification Information, Tax Information, Account Information, Contact Information, Securities Accounts, Tax Identity Numbers, Accounts With Other Banks, Id Details and .

Which entities were affected by each incident ?

Incident : Data Breach SCA0408523

Entity Name: Scalable Capital

Entity Type: Company

Industry: Financial Services

Customers Affected: 20000

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach SCA0408523

Communication Strategy: Notified affected clients via letter

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach SCA0408523

Type of Data Compromised: Identification information, Tax information, Account information, Contact information, Securities accounts, Tax identity numbers, Accounts with other banks, Id details

Number of Records Exposed: 20000

Sensitivity of Data: High

Investigation Status

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notified affected clients via letter.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Data Breach SCA0408523

Customer Advisories: Notified affected clients via letter

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Notified affected clients via letter.

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Breach SCA0408523

Root Causes: Extensive insider knowledge

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an Insider.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Identification information, Tax information, Account information, Contact information, Securities accounts, Tax identity numbers, Accounts with other banks, ID details and .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Account information, ID details, Contact information, Tax information, Tax identity numbers, Securities accounts, Identification information and Accounts with other banks.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 200.0.

Stakeholder and Customer Advisories

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued was an Notified affected clients via letter.

cve

Latest Global CVEs (Not Company-Specific)

Description

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.

Risk Information
cvss3
Base: 9.9
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description

FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow. `generate_state_token()` is always called with an empty `state_data` dict, so the resulting JWT only contains the fixed audience claim plus an expiration timestamp. On callback, the library merely checks that the JWT verifies under `state_secret` and is unexpired; there is no attempt to match the state value to the browser that initiated the OAuth request, no correlation cookie, and no server-side cache. Any attacker can hit `/authorize`, capture the server-generated state, finish the upstream OAuth flow with their own provider account, and then trick a victim into loading `.../callback?code=<attacker_code>&state=<attacker_state>`. Because the state JWT is valid for any client for \~1 hour, the victim’s browser will complete the flow. This leads to login CSRF. Depending on the app’s logic, the login CSRF can lead to an account takeover of the victim account or to the victim user getting logged in to the attacker's account. Version 15.0.2 contains a patch for the issue.

Risk Information
cvss3
Base: 5.9
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Description

FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.

Risk Information
cvss3
Base: 9.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 8.5
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss4
Base: 8.6
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

Risk Information
cvss3
Base: 9.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 8.5
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=scalable-capital' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge