Security by Default
Security at FundFrame
FundFrame is built around the security and operational standards institutional LPs require. ISO 27001 certified, EU-hosted, and engineered so the people who handle your data answer to the same regulators you do.

Certifications and regulatory alignment
ISO 27001
Certified · Active
Certified information security management system. Systematic protection of your data through rigorous controls, audited annually by an accredited third party.
View certificate on Trust CenterSOC 2 Compliant
Type II · In progress
Security controls aligned with SOC 2 Type II standards. Formal certification currently in progress.
DORA
Reg. (EU) 2022/2554
Requires
Operational resilience for regulated financial entities.
How FundFrame helps
EU-hosted infrastructure, enforced MFA, incident-response controls.
GDPR
Reg. (EU) 2016/679
Requires
Lawful, transparent, minimised processing of personal data.
How FundFrame helps
EU data residency, granular permissions, data-handling policies built in.
EU Data Residency
Frankfurt · Active
FundFrame is EU-first. Servers, backups, processing, and support tooling all run inside the EU. Your data stays under EU law, end to end.
Built in, not bolted on
Security is a default in the FundFrame stack, not a feature you enable. Every shipped change passes through controls designed with institutional LP requirements in mind.
Request our security documentationEnforced MFA
Multi-factor authentication is on for every user. Not an option, not a setting.
Encryption at Rest & In Transit
All data encrypted using AES-256 at rest and TLS 1.3 in transit. Your information is protected at every stage.
Access Controls
Role-based access control ensures only authorized users access your data.
Regular Penetration Testing
Penetration tests are run on FundFrame on a recurring schedule. Findings are triaged, remediated, and re-tested before sign-off.
Vulnerability Assessments
Continuous scanning of code, dependencies, and infrastructure.
Business Continuity
Redundant infrastructure, automated backups, and disaster recovery procedures ensure your data is always available.
Data Ownership
You own your data. Full export capabilities, no vendor lock-in, and clear data handling policies.
Vendor Management
Rigorous third-party security assessments ensure our entire supply chain meets institutional security standards.
Need the long form?
Security questionnaires, DPA templates, sub-processor lists, the full ISO 27001 SoA. Whatever your compliance team needs to sign off, we’ll send.