Resources / Security
Security at FundFrame.
Your team trusts FundFrame with its managers, its portfolio and its notes. This page sets out how that data is protected, where it is hosted and who has checked.
Visit the trust centerIndependently certified security and compliance.
FundFrame is ISO 27001 certified, SOC 2 Type II compliant, hosted in the EU and governed by GDPR. Your managers, your portfolio and your notes are handled to the standard an institutional investor is held to.
ISO 27001
FundFrame is certified to ISO 27001, the international standard for information security management. The certificate covers the platform and the company that runs it.
SOC 2 Type II
FundFrame is SOC 2 Type II compliant, the AICPA standard for how a service provider secures and handles customer data.
EU hosting
Your data is hosted in Frankfurt and stays in the EU. GDPR governs everything we hold, and the platform supports the operational resilience framework your institution runs under DORA.
How your data is protected.
The same controls apply to every customer from the first day. None of them are add-ons and none of them depend on your plan.
Enforced MFA
Multi-factor authentication is on for every user on your team. It is not an option and it cannot be switched off.
Encryption
Your data is encrypted with AES-256 at rest and TLS 1.3 in transit, so it is protected wherever it is.
Access control
Each user is an Admin, an Editor or a Viewer, so you decide who can change the data and who can only read it.
Penetration testing
FundFrame is penetration tested on a recurring schedule. Every finding is fixed and tested again before sign-off.
Vulnerability scanning
Our code, its dependencies and the infrastructure it runs on are scanned continuously.
Business continuity
Redundant infrastructure, automated backups and disaster recovery procedures keep your data available.
Your data stays yours
You own your data and can export every record whenever you want. There is no lock-in.
Vendor management
Every supplier that handles your data goes through a security assessment before we work with them.
The regulations behind the controls.
Regulated investors answer for the services they use. These are the two European rules that shape how FundFrame handles your data.
GDPR
Reg. (EU) 2016/679
What it asks
Personal data must be processed lawfully and transparently, and only as far as the purpose needs.
How FundFrame helps
Your data is hosted in the EU, access is set per user, and our data handling policies are built into the platform.
DORA
Reg. (EU) 2022/2554
What it asks
Regulated financial entities must manage the operational resilience of the ICT services they rely on.
How FundFrame helps
FundFrame runs on EU infrastructure with enforced MFA and incident response controls, which supports your own resilience framework.
Common questions
Something else? Get in touch.