Where your data lives.
We believe you should be able to see the machinery. askFinz doesn't run its own data centers — we build on a handful of best-in-class providers, mapped here by what each part does and the city it runs from, with the security certifications each provider holds. It's also how we keep askFinz fast for everyone, everywhere.
Requests are answered from the nearest of 300+ edge cities, so pages feel local wherever you open them.
Your files, code and backups live in European data centers — described here by what they do, not who runs them.
We don't run our own data centers. Every provider we build on is independently audited against ISO 27001, SOC 2, PCI DSS and more.
The map
9 functionsFaint dots are the global delivery network. Labelled points are the functions we run on those providers, shown by city. We name the role, never the vendor.
Each marker is a function we run, shown by city — not the company behind it. Click a point for detail.
How your data is protected
Your files are written to primary storage and simultaneously mirrored every 60 seconds to an independent system in a separate EU facility. If primary storage ever goes offline, the live mirror activates automatically — no manual steps, no restarts, no data loss beyond 60 seconds.
Your data lives here
Every file, workspace asset and upload. EU data center (Amsterdam). Direct, low-latency access for all app reads and writes.
Always up to date
Receives a live mirror sync every 60 seconds. Completely separate infrastructure — an outage at A cannot affect B. EU data center (Frankfurt, Germany).
Already a live mirror — B takes over instantly with zero seeding delay. All your data is available immediately, not just recent files.
When A comes back online, B syncs all data written during the outage back to A automatically — then A resumes as primary with no manual steps.
Maximum data loss in any failure scenario — the live mirror syncs every 60 seconds.
No manual steps, no restarts required. All backends switch automatically within 60 seconds of a failure being detected.
The live mirror holds your complete dataset — not just recent files — so everything is accessible the moment failover occurs.
What runs where — and how it's protected
Primary object storage
European Union (Netherlands)Holds your files, media and encrypted data at rest. First-line storage for every upload and workspace asset.
Object storage backup (live mirror)
European Union (Germany)Live mirror of all primary object storage — syncs every 60 seconds. Activates automatically if primary storage is unavailable, with instant failover and no data loss beyond the last 60-second window.
Content delivery & DNS
Global edge — 300+ citiesRoutes every request to the nearest edge and resolves our domains — the reason pages load fast wherever you are.
Payments & billing
European Union (Ireland)Processes subscriptions and payments — card details go straight to a certified processor, never to askFinz.
Source code & version control
European Union (Netherlands)Stores and versions the platform's source code and build history.
Media & file storage
European Union (Netherlands)Serves uploaded media and documents from close to you.
SMS & voice communications
Global carrier-grade data centersDelivers verification codes, alerts and voice calls.
Transactional email
European Union (Ireland)Sends account, security and notification emails.
Live stream ingest
European Union (Finland)Receives and packages live video before it reaches viewers.
What the certifications mean
The badges above aren't ours to claim — they're held by the providers we build on. Here's what each one is, and why it matters for your data.
Information security management
- ISO/IEC 27001
The international standard for an Information Security Management System (ISMS).
How it helps — Our providers run a systematic, independently audited security program, so your data sits on rigorously managed foundations.
- ISO/IEC 27017
Cloud-specific security controls that extend ISO 27001.
How it helps — Cloud services we build on follow controls designed for cloud risks like tenant isolation and admin operations.
- SOC 2 Type II
An AICPA audit of security, availability and confidentiality controls measured over a period of time.
How it helps — Independent proof the providers' controls actually operate day-to-day — not just on paper.
- SOC 1
An AICPA report on controls relevant to financial reporting.
How it helps — Assurance around billing- and finance-related processing.
- SOC 3
A plain, publicly shareable version of the confidential SOC 2 audit.
How it helps — Lets a provider share independent proof of its security controls openly — no confidentiality agreement required.
- CSA STAR
The Cloud Security Alliance's Security, Trust, Assurance & Risk program.
How it helps — Cloud-specific, registry-published transparency on a provider's security posture.
- BSI C5
Germany's Federal Office for Information Security (BSI) cloud criteria catalogue; Type 2 tests operating effectiveness.
How it helps — A rigorous EU cloud-security benchmark that incorporates ISO 27001.
- Audited TOMs
Technical & Organizational Measures under GDPR Art. 32, externally audited.
How it helps — Documented, verified safeguards specifically around personal-data processing.
- Cyber Essentials
A UK NCSC-backed baseline cyber-security certification.
How it helps — Independently verified baseline cyber hygiene.
- TISAX
The Trusted Information Security Assessment Exchange.
How it helps — Shared, audited information-security assurance across vendors.
Privacy & data protection
- GDPR / UK GDPR
The EU and UK General Data Protection Regulation.
How it helps — Lawful processing and your data-subject rights are honored across the EU and UK.
- EU Model Clauses
Standard Contractual Clauses for lawful international data transfers.
How it helps — A lawful basis for any cross-border data flow.
- ISO/IEC 27701
An international privacy-management standard that extends ISO 27001 from security into how personal data is handled.
How it helps — Shows a provider runs privacy as a formal, audited program — and their evidence directly supports our own GDPR compliance.
- ISO/IEC 27018
A code of practice for protecting personal data (PII) in public clouds.
How it helps — Constrains how providers handle personal data — e.g. it isn't used for advertising.
- EU Cloud CoC
A GDPR Article 40 approved code of conduct for cloud providers.
How it helps — The provider's GDPR compliance is independently verified for its cloud services.
- CCPA / CPRA
California's consumer privacy laws.
How it helps — Privacy rights — access, deletion and opt-out — for California users.
- Global CBPR / PRP
International Cross-Border Privacy Rules & Privacy Recognition for Processors certifications.
How it helps — A recognized framework for moving data across borders responsibly.
Payments & regulated data
- PCI DSS
The Payment Card Industry Data Security Standard (v4.0).
How it helps — Card data is handled only in a PCI-compliant environment — safe billing and payments.
- PCI DSS Level 1
The highest PCI DSS tier, for processors handling the largest card volumes, audited annually by a Qualified Security Assessor.
How it helps — Card payments run through a top-tier-certified processor — your card details never touch askFinz.
- PSD2 / SCA
The EU Payment Services Directive 2 and its Strong Customer Authentication requirement.
How it helps — European card payments are authenticated to EU regulatory standards, such as a second factor at checkout.
- 3-D Secure
An EMV authentication protocol (3DS2) that verifies the cardholder during online payments.
How it helps — Adds a fraud check and shifts liability, protecting you and us on card payments.
- HIPAA
The US health-data protection law (Health Insurance Portability and Accountability Act); a Business Associate Agreement is available. Covers protected health information (PHI) and ePHI in compliance with HIPAA and HITECH, as administered by HHS.
How it helps — Lets us and healthcare customers handle protected health information where needed, such as the med workspace.
- CJIS
Criminal Justice Information Services — standards set by a division of the US FBI for the privacy, security, durability and protection of Criminal Justice Information (CJI) and other critical data.
How it helps — Storage infrastructure supports law-enforcement and justice-sector customers who must maintain CJIS compliance.
- FERPA
The Family Educational Rights and Privacy Act — imposes specific technical and administrative requirements for education IT planners, InfoSec organizations and compliance officers receiving U.S. Department of Education aid.
How it helps — Educational institutions and EdTech customers can store and process student data in compliance with FERPA.
- SEC / SEA
U.S. Securities and Exchange Commission and Securities Exchange Act rules (17 CFR 240.17a-4) — third-party record-keeping services must provide an undertaking letter to customer organizations. Effective May 2023.
How it helps — Financial-services customers who are SEC-regulated can obtain an alternate undertaking letter for compliant record retention.
- HDS
The EU 'Health Data Hosting' (Hébergeur de Données de Santé) certification.
How it helps — Health data can be hosted within the EEA to a regulated standard.
- ITAR
US International Traffic in Arms Regulations data-handling controls.
How it helps — Providers support controlled-data handling, e.g. US-person access restrictions.
Government & national security programs
- FedRAMP
US federal cloud security authorization (Moderate).
How it helps — A government-grade security baseline underpins our edge and storage.
- NIST 800-53 / FISMA
The US federal security control catalogue and risk baseline (High).
How it helps — A stringent, well-known control baseline underpins the infrastructure.
- GovRAMP
US state & local government cloud authorization (formerly StateRAMP).
How it helps — Public-sector-grade assurance.
- TX-RAMP
The Texas Risk & Authorization Management Program.
How it helps — Meets Texas public-sector security requirements.
- KRITIS / NIS-2
German & EU critical-infrastructure operator obligations, certified per §8a BSIG.
How it helps — Infrastructure held to critical-service resilience and security duties.
- ENS
Spain's Esquema Nacional de Seguridad (National Security Framework).
How it helps — Meets the Spanish national security framework.
- IRAP
Australia's Information Security Registered Assessors Program.
How it helps — Australian government-grade security assessment.
- ISMAP
Japan's government cloud security assessment program.
How it helps — Japanese public-sector-grade assurance.
Reliability, quality & sustainability
- ISO 22301
The standard for business continuity management.
How it helps — Providers plan for disruptions, so the platform stays available through incidents.
- ISO/IEC 20000-1
The IT service management standard.
How it helps — Mature, repeatable operations behind the services we depend on.
- ISO 9001
The quality management system standard.
How it helps — Consistent, documented service quality.
- Uptime Tier
Uptime Institute Tier certification for data-center design, facility and operations.
How it helps — Physical infrastructure engineered for high availability.
- Climate Neutral DC Pact
A European pledge for carbon-neutral data centers by 2030.
How it helps — Greener hosting for your workloads.
- TPN
Trusted Partner Network (Blue Shield), aligned to MPA content-security best practices.
How it helps — Media and content stored to film-industry security standards.
- HECVAT
The Higher-Education Community Vendor Assessment Tool.
How it helps — Vetted for use by universities and research institutions.
- VPAT / Section 508
A Voluntary Product Accessibility Template against Section 508 guidelines.
How it helps — Services remain accessible to users with disabilities.
Provider data-protection practices
- TLS 1.3
The latest transport-layer encryption protocol.
How it helps — Data in transit is strongly encrypted everywhere it crosses a network.
- Encryption at rest
Stored data is encrypted, with row-level encryption for sensitive tables.
How it helps — Stored data is unreadable if storage media are ever compromised.
- Point-in-time backups
30-day retention, globally replicated backups.
How it helps — Recoverability against data loss or a regional outage.
- Annual pen-testing
Third-party offensive security testing at least annually.
How it helps — Vulnerabilities are found and fixed proactively.
Certifications are held by the independent providers that operate each location — not by askFinz — and are subject to their own audit cycles. We track them as part of our vendor due-diligence.
Questions about data residency or a specific certificate? Read our security overview or get in touch.
Trust center