Trust Center: Security, transparency and compliance – built in from the start.
FinAPU was developed specifically for use by regulated financial institutions. That is why information security, data protection and regulatory compliance form the foundation of our platform. Our Trust Center brings together all relevant information on security measures, certifications and regulatory standards.
Trust is not created by individual measures or certifications. It is built through consistent decisions – in the development of our platform, the selection of our partners and the way we handle data.
Our aim is not to add information security, data protection and compliance retrospectively, but to consider them from the outset in the architecture, development and ongoing operation of our platform. We therefore rely on European infrastructure, established security standards and traceable processes. This creates the foundation for a secure, auditable and reliable long-term platform for regulated financial institutions.
| Area | Implementation at FinAPU | |
|---|---|---|
| Information security | ISO/IEC 27001-certified ISMS | |
| Infrastructure | European cloud infrastructure | |
| Privacy | GDPR-compliant data processing | |
| Access control | Role-based access and authorization concepts | |
| Operational resilience | DORA-oriented processes | |
| Transparency | Documented and auditable procedures |
How we build trust
Our five core pillars shape the continuous development of our platform. Together, they form the foundation for information security, data protection and regulatory compliance in the day-to-day use of FinAPU by financial institutions.
Information security
Protecting information, systems and processes is fundamental to our platform. Our ISO/IEC 27001-certified Information Security Management System (ISMS) ensures that information security is systematically planned, implemented and continuously improved. This is complemented by clearly defined security measures and role-based access controls to ensure secure operations.
- ISO/IEC 27001
- Information Security Management System (ISMS)
- Security by Design
- Role-based access and authorization concepts
Data Protection
Data protection is an integral part of our platform. FinAPU processes personal data in accordance with the General Data Protection Regulation (GDPR). The principle of data minimisation and clearly defined processes provide the foundation for processing sensitive corporate and financial data in compliance with data protection requirements.
- General Data Protection Regulation (GDPR)
- Data processing in compliance with data protection requirements
- Data minimisation
- Defined data protection processes
Governance
Information security is a continuous process and an integral part of our corporate governance. Clear responsibilities, regular training, defined processes and internal and external audits ensure that security measures are continuously reviewed and improved.
- Clear responsibilities
- Regular training
- Continuous improvement
- Internal and external audits
Operational resilience
The Digital Operational Resilience Act (DORA) sets requirements for the digital operational resilience of financial institutions. FinAPU supports banks and other regulated companies in meeting these requirements through structured processes and measures for business continuity, incident management and continuous monitoring.
- Digital Operational Resilience Act (DORA)
- Business Continuity
- Incident Management
- Continuous monitoring
Transparency
Trust requires traceability. In regulated environments in particular, documented and auditable processes are essential for robust decisions. We therefore place great emphasis on documented processes, transparent methodologies and auditable results that can be reviewed at any time.
- Traceable methodologies
- Documented processes
- Auditable results
- Explainability
Data Sovereignty
Our customers retain control over their data. FinAPU processes customer data exclusively within Europe and within the scope of the agreed services. Customer data is not used to train general-purpose AI models or publicly available large language models.
- Data processing within Europe
- European cloud infrastructure
- Purpose-limited data processing
- No training of general-purpose AI models using customer data
Certifications & Assurance
Trust requires verifiable standards. It is not based on our statements alone, but on traceable processes and independent assurance. We therefore have our security measures regularly reviewed and align them with recognised standards and regulatory requirements. The following certifications and assurance measures provide an overview of the key foundations of our security and compliance approach.
ISO/IEC 27001
ISO/IEC 27001 is the internationally recognised standard for information security management. It confirms that FinAPU has established a systematic Information Security Management System (ISMS) and that information security is continuously planned, implemented, reviewed and improved.
For our customers, this means that information security is based on clearly defined processes, regular audits and the continuous improvement of security measures.
Cyber Trust Austria
The Cyber Trust Austria quality label confirms that FinAPU meets defined cybersecurity and information security requirements. The label is awarded on the basis of a structured catalogue of criteria and is reviewed regularly.
For our customers, this means that the independent assessment complements our internal security measures and provides additional transparency regarding our security level.
DORA
The Digital Operational Resilience Act (DORA) establishes a harmonised European legal framework for the digital operational resilience of financial institutions. FinAPU was developed for regulated environments and supports financial institutions in meeting increasing requirements relating to information security, governance and third-party risk.
For our customers, this means that our platform takes the requirements of regulated financial institutions into account from development through operation and supports them in implementing their regulatory obligations.
Data Protection & European Infrastructure
Protecting sensitive corporate and financial data begins with choosing the right infrastructure. FinAPU therefore deliberately relies on European cloud infrastructure and processes personal data in accordance with the General Data Protection Regulation (GDPR).
For our customers, this means that data remains within Europe and is processed in accordance with European data protection standards.
Security & Compliance Services
For customers, partners and prospective customers, we provide additional information on our security and compliance measures upon request. This enables us to support security assessments, due diligence processes and regulatory reviews efficiently and transparently.
Depending on requirements, we provide information including:
- ISO/IEC 27001 certificate
- Information on our Information Security Management System (ISMS)
- Data protection information
- Support with security and due diligence questionnaires
- Contact for information security and compliance
Frequently Asked Questions
FinAPU relies on European infrastructure and processes customer data exclusively within Europe. This means that data remains subject to European data protection law and is processed in accordance with the GDPR.
Yes. FinAPU operates an Information Security Management System (ISMS) certified in accordance with ISO/IEC 27001. The certification confirms that information security is systematically planned, implemented and continuously improved.
No. FinAPU does not use customer data to train general-purpose AI models or publicly available large language models. Data is processed solely for the provision of the agreed services and is not used for third-party training purposes.
Yes. FinAPU was developed for regulated financial institutions and supports them in meeting regulatory requirements, particularly in the areas of information security, governance and operational resilience.
FinAPU uses the European cloud infrastructure of A1 Exoscale. In doing so, we deliberately rely on a European hosting partner and a regulatory environment close to our customers.
At FinAPU, information security is based on a multi-layered approach. This includes a certified ISMS, role-based authorization concepts, encryption, continuous monitoring and defined processes for incident management and business continuity.
Traceability is a core element of our platform. Processes, methodologies and results are documented and designed to be understandable and auditable for customers and auditors.
FinAPU supports customers throughout information security, compliance and due diligence processes by providing relevant assurance documentation, dedicated contacts and supplementary information.
Questions about security or compliance?
Would you like to learn more about our security measures, certifications or regulatory standards? Our CISO is happy to assist with questions relating to information security, due diligence and security assessments.
Stefan Weiss
Chief Information Security Officer (CISO)