Trust Center: Security, transparency and compliance – built in from the start.

FinAPU was developed specifically for use by regulated financial institutions. That is why information security, data protection and regulatory compliance form the foundation of our platform. Our Trust Center brings together all relevant information on security measures, certifications and regulatory standards.

Go to FAQs

Trust is not created by individual measures or certifications. It is built through consistent decisions – in the development of our platform, the selection of our partners and the way we handle data.

Our aim is not to add information security, data protection and compliance retrospectively, but to consider them from the outset in the architecture, development and ongoing operation of our platform. We therefore rely on European infrastructure, established security standards and traceable processes. This creates the foundation for a secure, auditable and reliable long-term platform for regulated financial institutions.

AreaImplementation at FinAPU 
Information securityISO/IEC 27001-certified ISMS
InfrastructureEuropean cloud infrastructure
PrivacyGDPR-compliant data processing
Access controlRole-based access and authorization concepts
Operational resilienceDORA-oriented processes
TransparencyDocumented and auditable procedures

How we build trust

Our five core pillars shape the continuous development of our platform. Together, they form the foundation for information security, data protection and regulatory compliance in the day-to-day use of FinAPU by financial institutions.

Information security

Protecting information, systems and processes is fundamental to our platform. Our ISO/IEC 27001-certified Information Security Management System (ISMS) ensures that information security is systematically planned, implemented and continuously improved. This is complemented by clearly defined security measures and role-based access controls to ensure secure operations.

  • ISO/IEC 27001
  • Information Security Management System (ISMS)
  • Security by Design
  • Role-based access and authorization concepts

Data Protection

Data protection is an integral part of our platform. FinAPU processes personal data in accordance with the General Data Protection Regulation (GDPR). The principle of data minimisation and clearly defined processes provide the foundation for processing sensitive corporate and financial data in compliance with data protection requirements.

  • General Data Protection Regulation (GDPR)
  • Data processing in compliance with data protection requirements
  • Data minimisation
  • Defined data protection processes

Governance

Information security is a continuous process and an integral part of our corporate governance. Clear responsibilities, regular training, defined processes and internal and external audits ensure that security measures are continuously reviewed and improved.

  • Clear responsibilities
  • Regular training
  • Continuous improvement
  • Internal and external audits

Operational resilience

The Digital Operational Resilience Act (DORA) sets requirements for the digital operational resilience of financial institutions. FinAPU supports banks and other regulated companies in meeting these requirements through structured processes and measures for business continuity, incident management and continuous monitoring.

Transparency

Trust requires traceability. In regulated environments in particular, documented and auditable processes are essential for robust decisions. We therefore place great emphasis on documented processes, transparent methodologies and auditable results that can be reviewed at any time.

  • Traceable methodologies
  • Documented processes
  • Auditable results
  • Explainability

Data Sovereignty

Our customers retain control over their data. FinAPU processes customer data exclusively within Europe and within the scope of the agreed services. Customer data is not used to train general-purpose AI models or publicly available large language models.

  • Data processing within Europe
  • European cloud infrastructure
  • Purpose-limited data processing
  • No training of general-purpose AI models using customer data

Certifications & Assurance

Trust requires verifiable standards. It is not based on our statements alone, but on traceable processes and independent assurance. We therefore have our security measures regularly reviewed and align them with recognised standards and regulatory requirements. The following certifications and assurance measures provide an overview of the key foundations of our security and compliance approach.

ISO/IEC 27001

ISO/IEC 27001 is the internationally recognised standard for information security management. It confirms that FinAPU has established a systematic Information Security Management System (ISMS) and that information security is continuously planned, implemented, reviewed and improved.

For our customers, this means that information security is based on clearly defined processes, regular audits and the continuous improvement of security measures.

→ View ISO certificate

ISO/IEC 27001

Cyber Trust Austria

The Cyber Trust Austria quality label confirms that FinAPU meets defined cybersecurity and information security requirements. The label is awarded on the basis of a structured catalogue of criteria and is reviewed regularly.

For our customers, this means that the independent assessment complements our internal security measures and provides additional transparency regarding our security level.

→ Learn more

Cyber Trust Austria

DORA

The Digital Operational Resilience Act (DORA) establishes a harmonised European legal framework for the digital operational resilience of financial institutions. FinAPU was developed for regulated environments and supports financial institutions in meeting increasing requirements relating to information security, governance and third-party risk.

For our customers, this means that our platform takes the requirements of regulated financial institutions into account from development through operation and supports them in implementing their regulatory obligations.

→ Learn more

Data Protection & European Infrastructure

Protecting sensitive corporate and financial data begins with choosing the right infrastructure. FinAPU therefore deliberately relies on European cloud infrastructure and processes personal data in accordance with the General Data Protection Regulation (GDPR).

For our customers, this means that data remains within Europe and is processed in accordance with European data protection standards.

→ Learn more

Security & Compliance Services

For customers, partners and prospective customers, we provide additional information on our security and compliance measures upon request. This enables us to support security assessments, due diligence processes and regulatory reviews efficiently and transparently.

Depending on requirements, we provide information including:

  • ISO/IEC 27001 certificate
  • Information on our Information Security Management System (ISMS)
  • Data protection information
  • Support with security and due diligence questionnaires
  • Contact for information security and compliance

Contact FinAPU Security & Compliance

Frequently Asked Questions

Questions about security or compliance?

Would you like to learn more about our security measures, certifications or regulatory standards? Our CISO is happy to assist with questions relating to information security, due diligence and security assessments.

Stefan Weiss
Chief Information Security Officer (CISO)

Get in touch