Resources / Security

Security at FundFrame.

Your team trusts FundFrame with its managers, its portfolio and its notes. This page sets out how that data is protected, where it is hosted and who has checked.

Visit the trust center

Independently certified security and compliance.

FundFrame is ISO 27001 certified, SOC 2 Type II compliant, hosted in the EU and governed by GDPR. Your managers, your portfolio and your notes are handled to the standard an institutional investor is held to.

ISO 27001

FundFrame is certified to ISO 27001, the international standard for information security management. The certificate covers the platform and the company that runs it.

SOC 2 Type II

FundFrame is SOC 2 Type II compliant, the AICPA standard for how a service provider secures and handles customer data.

EU hosting

Your data is hosted in Frankfurt and stays in the EU. GDPR governs everything we hold, and the platform supports the operational resilience framework your institution runs under DORA.

How your data is protected.

The same controls apply to every customer from the first day. None of them are add-ons and none of them depend on your plan.

Enforced MFA

Multi-factor authentication is on for every user on your team. It is not an option and it cannot be switched off.

Encryption

Your data is encrypted with AES-256 at rest and TLS 1.3 in transit, so it is protected wherever it is.

Access control

Each user is an Admin, an Editor or a Viewer, so you decide who can change the data and who can only read it.

Penetration testing

FundFrame is penetration tested on a recurring schedule. Every finding is fixed and tested again before sign-off.

Vulnerability scanning

Our code, its dependencies and the infrastructure it runs on are scanned continuously.

Business continuity

Redundant infrastructure, automated backups and disaster recovery procedures keep your data available.

Your data stays yours

You own your data and can export every record whenever you want. There is no lock-in.

Vendor management

Every supplier that handles your data goes through a security assessment before we work with them.

The regulations behind the controls.

Regulated investors answer for the services they use. These are the two European rules that shape how FundFrame handles your data.

GDPR

Reg. (EU) 2016/679

What it asks

Personal data must be processed lawfully and transparently, and only as far as the purpose needs.

How FundFrame helps

Your data is hosted in the EU, access is set per user, and our data handling policies are built into the platform.

DORA

Reg. (EU) 2022/2554

What it asks

Regulated financial entities must manage the operational resilience of the ICT services they rely on.

How FundFrame helps

FundFrame runs on EU infrastructure with enforced MFA and incident response controls, which supports your own resilience framework.

Common questions

Something else? Get in touch.

Everything your team keeps in FundFrame is encrypted with AES-256 at rest and TLS 1.3 in transit. That covers the manager records and meeting notes in the CRM as much as the statements and notices Portfolio Monitoring reads.
In Frankfurt, and your data stays inside the European Union. GDPR governs everything FundFrame holds, and the platform supports the operational resilience framework your institution runs under DORA.
Only the people on your team you give access to. Multi-factor authentication is on for every user and cannot be switched off, and each user is an Admin, an Editor or a Viewer, so you decide who can change the data and who can only read it.
FundFrame is ISO 27001 certified and SOC 2 Type II compliant, and the ISO 27001 certificate covers both the platform and the company that runs it. The platform is also penetration tested on a recurring schedule, and every finding is fixed and tested again before sign-off.
FundFrame deletes it. Before that happens, your team can export every record, from the manager records and notes to the fund figures, so nothing you have built up is lost.
The trust center holds our certifications and security policies. If your team needs something else for a due diligence questionnaire or a vendor review, get in touch and we will help.

Talk to our team about how your data is handled.

Book Demo