Executive Summary
AI-generated analysis for Akoya
Akoya (akoya.com) is an Open Finance and API-connected data sharing vendor assessed at Risk Tier 3 (Moderate Risk) with a 90% confidence score. Operating in the financial data infrastructure space, Akoya presents a mixed risk profile characterized by strong foundational security controls alongside a small number of transparency and documentation gaps. Akoya demonstrates meaningful security strengths across several dimensions:
Key Findings
- The domain carries a 27-year registration history and a 26-year archived web presence, indicating an established and stable operator.
- Infrastructure is protected behind Cloudflare CDN with a clean threat score of 0, zero known CVEs, and no malware or phishing flags across Malware detection service and web security scanning service.
- Domain SSL/TLS configuration employs TLS 1.3 with AES-256-GCM encryption, with no weak protocols or ciphers detected.
- Sanctions screening across OFAC, EU, and UN watchlists returned zero matches, and no adverse media was found in current or historical searches.
- SOC 2 compliance is claimed on the vendor's trust page (https://akoya.com/blog/soc2-and-why-it-matters), which is a positive signal for a financial data vendor;
Area Requiring Attention
however, the full Type II report has not been independently verified. Three areas require attention before onboarding can be finalized. First, 11 open ports were detected on Akoya's infrastructure — at the upper boundary of a typical Cloudflare-managed footprint — and while no CVEs are associated, the full necessity of all exposed services warrants confirmation. Second, no publicly accessible subprocessor or third-party vendor page was found, limiting supply chain visibility for a vendor handling financial data. Third, no public AI data usage policy was discovered; given the sensitivity of financial data, this creates an undocumented risk surface if AI processing is used in any form. Additionally, Akoya's HTTP security header configuration received a C+ grade (60/100) from HTTP security scanner, indicating room for improvement on the marketing site. Overall, Akoya presents as a functional financial data infrastructure vendor with solid core security hygiene and a long-established domain, but documentation gaps in subprocessor transparency and AI data handling introduce moderate compliance risk for technology buyers with SOC 2 obligations. Conditional approval is warranted pending resolution of the identified requirements.
Independence Statement
All evidence in this report was independently sourced from external public registries, DNS infrastructure, threat intelligence feeds, web archives, and sanctions databases without vendor participation or disclosure.