Skip to main content
Private access is opening up — request an invite
askFinz
Infrastructure · Trust

Where your data lives.

We believe you should be able to see the machinery. askFinz doesn't run its own data centers — we build on a handful of best-in-class providers, mapped here by what each part does and the city it runs from, with the security certifications each provider holds. It's also how we keep askFinz fast for everyone, everywhere.

Served from everywhere

Requests are answered from the nearest of 300+ edge cities, so pages feel local wherever you open them.

Homed in the EU

Your files, code and backups live in European data centers — described here by what they do, not who runs them.

Built on certified providers

We don't run our own data centers. Every provider we build on is independently audited against ISO 27001, SOC 2, PCI DSS and more.

The map

9 functions

Faint dots are the global delivery network. Labelled points are the functions we run on those providers, shown by city. We name the role, never the vendor.

Each marker is a function we run, shown by city — not the company behind it. Click a point for detail.

How your data is protected

Your files are written to primary storage and simultaneously mirrored every 60 seconds to an independent system in a separate EU facility. If primary storage ever goes offline, the live mirror activates automatically — no manual steps, no restarts, no data loss beyond 60 seconds.

Storage architecture2-tier · auto-failover · <1 min RPO
APrimary storage

Your data lives here

Every file, workspace asset and upload. EU data center (Amsterdam). Direct, low-latency access for all app reads and writes.

SOC 2ISO 27001HIPAAGDPR
every 60 s
BLive mirror backup

Always up to date

Receives a live mirror sync every 60 seconds. Completely separate infrastructure — an outage at A cannot affect B. EU data center (Frankfurt, Germany).

SOC 2 Type 2ISO 27001:2022HIPAAPCIGDPRSEC/FINRA
If Provider A goes offline
BLive mirror backup

Already a live mirror — B takes over instantly with zero seeding delay. All your data is available immediately, not just recent files.

instant
AAuto-restore on recovery

When A comes back online, B syncs all data written during the outage back to A automatically — then A resumes as primary with no manual steps.

Because B is a live mirror updated every 60 seconds — not a periodic cold snapshot — the maximum data loss in any failure scenario is 60 seconds. All data, not just recent files, is immediately available.
A — Primary object storage (EU, Amsterdam)
B — Live mirror backup (EU, Frankfurt)
< 1 min
Recovery Point Objective

Maximum data loss in any failure scenario — the live mirror syncs every 60 seconds.

Automatic
Failover

No manual steps, no restarts required. All backends switch automatically within 60 seconds of a failure being detected.

100%
Data availability

The live mirror holds your complete dataset — not just recent files — so everything is accessible the moment failover occurs.

By function

What runs where — and how it's protected

Primary object storage

European Union (Netherlands)

Holds your files, media and encrypted data at rest. First-line storage for every upload and workspace asset.

Certified against
SOC 2 Type 2ISO 27001HIPAAGDPR & UK GDPRCCPA / CPRAPCI-DSSGovRAMPTX-RAMPTPN Blue ShieldHECVATVPAT / Section 508

Object storage backup (live mirror)

European Union (Germany)

Live mirror of all primary object storage — syncs every 60 seconds. Activates automatically if primary storage is unavailable, with instant failover and no data loss beyond the last 60-second window.

Certified against
SOC 2 Type 2ISO/IEC 27001:2022HIPAAPCIGDPRSEC / FINRAData Center Security

Content delivery & DNS

Global edge — 300+ cities

Routes every request to the nearest edge and resolves our domains — the reason pages load fast wherever you are.

Certified against
ISO 27001 / 27701SOC 2 Type IIC5 Type 2HIPAAPCI DSS 4.0.1CSA STARENSIRAPISMAPCyber EssentialsEU Cloud CoC

Payments & billing

European Union (Ireland)

Processes subscriptions and payments — card details go straight to a certified processor, never to askFinz.

Certified against
PCI DSS Level 1SOC 1 / 2 Type IISOC 3ISO/IEC 27001PSD2 / SCA3-D SecureGDPRGlobal CBPR / PRPEncryption at rest

Source code & version control

European Union (Netherlands)

Stores and versions the platform's source code and build history.

Certified against
ISO/IEC 27001ISO/IEC 27017ISO/IEC 27018ISO/IEC 27701ISO 22301ISO 9001SOC 1 / 2 / 3CSA STARPCI DSSGDPR

Media & file storage

European Union (Netherlands)

Serves uploaded media and documents from close to you.

Certified against
ISO 27001:2022ISO 27701:2019ISO 27018:2019ISO 27017:2015SOC 2 Type IIPCI DSS 4.0FedRAMP ModerateGovRAMPC5:2020EU Cloud CoCGlobal CBPR / PRP

SMS & voice communications

Global carrier-grade data centers

Delivers verification codes, alerts and voice calls.

Certified against
ISO 27001SOC 1 / 2 Type IIPCI DSSHIPAAHDSNIST 800-53 / FISMA HighITARTISAXUptime TierISO 22301 / 20000 / 9001Climate Neutral DC Pact

Transactional email

European Union (Ireland)

Sends account, security and notification emails.

Certified against
SOC 2 Type IIGDPRTLS 1.3Encryption at restPoint-in-time backupsAnnual pen-testing

Live stream ingest

European Union (Finland)

Receives and packages live video before it reaches viewers.

Certified against
ISO/IEC 27001:2022BSI C5 Type 2KRITIS / NIS-2PCI DSS 4.0Audited TOMs
Compliance at a glance

What the certifications mean

The badges above aren't ours to claim — they're held by the providers we build on. Here's what each one is, and why it matters for your data.

Information security management

  • ISO/IEC 27001

    The international standard for an Information Security Management System (ISMS).

    How it helps — Our providers run a systematic, independently audited security program, so your data sits on rigorously managed foundations.

  • ISO/IEC 27017

    Cloud-specific security controls that extend ISO 27001.

    How it helps — Cloud services we build on follow controls designed for cloud risks like tenant isolation and admin operations.

  • SOC 2 Type II

    An AICPA audit of security, availability and confidentiality controls measured over a period of time.

    How it helps — Independent proof the providers' controls actually operate day-to-day — not just on paper.

  • SOC 1

    An AICPA report on controls relevant to financial reporting.

    How it helps — Assurance around billing- and finance-related processing.

  • SOC 3

    A plain, publicly shareable version of the confidential SOC 2 audit.

    How it helps — Lets a provider share independent proof of its security controls openly — no confidentiality agreement required.

  • CSA STAR

    The Cloud Security Alliance's Security, Trust, Assurance & Risk program.

    How it helps — Cloud-specific, registry-published transparency on a provider's security posture.

  • BSI C5

    Germany's Federal Office for Information Security (BSI) cloud criteria catalogue; Type 2 tests operating effectiveness.

    How it helps — A rigorous EU cloud-security benchmark that incorporates ISO 27001.

  • Audited TOMs

    Technical & Organizational Measures under GDPR Art. 32, externally audited.

    How it helps — Documented, verified safeguards specifically around personal-data processing.

  • Cyber Essentials

    A UK NCSC-backed baseline cyber-security certification.

    How it helps — Independently verified baseline cyber hygiene.

  • TISAX

    The Trusted Information Security Assessment Exchange.

    How it helps — Shared, audited information-security assurance across vendors.

Privacy & data protection

  • GDPR / UK GDPR

    The EU and UK General Data Protection Regulation.

    How it helps — Lawful processing and your data-subject rights are honored across the EU and UK.

  • EU Model Clauses

    Standard Contractual Clauses for lawful international data transfers.

    How it helps — A lawful basis for any cross-border data flow.

  • ISO/IEC 27701

    An international privacy-management standard that extends ISO 27001 from security into how personal data is handled.

    How it helps — Shows a provider runs privacy as a formal, audited program — and their evidence directly supports our own GDPR compliance.

  • ISO/IEC 27018

    A code of practice for protecting personal data (PII) in public clouds.

    How it helps — Constrains how providers handle personal data — e.g. it isn't used for advertising.

  • EU Cloud CoC

    A GDPR Article 40 approved code of conduct for cloud providers.

    How it helps — The provider's GDPR compliance is independently verified for its cloud services.

  • CCPA / CPRA

    California's consumer privacy laws.

    How it helps — Privacy rights — access, deletion and opt-out — for California users.

  • Global CBPR / PRP

    International Cross-Border Privacy Rules & Privacy Recognition for Processors certifications.

    How it helps — A recognized framework for moving data across borders responsibly.

Payments & regulated data

  • PCI DSS

    The Payment Card Industry Data Security Standard (v4.0).

    How it helps — Card data is handled only in a PCI-compliant environment — safe billing and payments.

  • PCI DSS Level 1

    The highest PCI DSS tier, for processors handling the largest card volumes, audited annually by a Qualified Security Assessor.

    How it helps — Card payments run through a top-tier-certified processor — your card details never touch askFinz.

  • PSD2 / SCA

    The EU Payment Services Directive 2 and its Strong Customer Authentication requirement.

    How it helps — European card payments are authenticated to EU regulatory standards, such as a second factor at checkout.

  • 3-D Secure

    An EMV authentication protocol (3DS2) that verifies the cardholder during online payments.

    How it helps — Adds a fraud check and shifts liability, protecting you and us on card payments.

  • HIPAA

    The US health-data protection law (Health Insurance Portability and Accountability Act); a Business Associate Agreement is available. Covers protected health information (PHI) and ePHI in compliance with HIPAA and HITECH, as administered by HHS.

    How it helps — Lets us and healthcare customers handle protected health information where needed, such as the med workspace.

  • CJIS

    Criminal Justice Information Services — standards set by a division of the US FBI for the privacy, security, durability and protection of Criminal Justice Information (CJI) and other critical data.

    How it helps — Storage infrastructure supports law-enforcement and justice-sector customers who must maintain CJIS compliance.

  • FERPA

    The Family Educational Rights and Privacy Act — imposes specific technical and administrative requirements for education IT planners, InfoSec organizations and compliance officers receiving U.S. Department of Education aid.

    How it helps — Educational institutions and EdTech customers can store and process student data in compliance with FERPA.

  • SEC / SEA

    U.S. Securities and Exchange Commission and Securities Exchange Act rules (17 CFR 240.17a-4) — third-party record-keeping services must provide an undertaking letter to customer organizations. Effective May 2023.

    How it helps — Financial-services customers who are SEC-regulated can obtain an alternate undertaking letter for compliant record retention.

  • HDS

    The EU 'Health Data Hosting' (Hébergeur de Données de Santé) certification.

    How it helps — Health data can be hosted within the EEA to a regulated standard.

  • ITAR

    US International Traffic in Arms Regulations data-handling controls.

    How it helps — Providers support controlled-data handling, e.g. US-person access restrictions.

Government & national security programs

  • FedRAMP

    US federal cloud security authorization (Moderate).

    How it helps — A government-grade security baseline underpins our edge and storage.

  • NIST 800-53 / FISMA

    The US federal security control catalogue and risk baseline (High).

    How it helps — A stringent, well-known control baseline underpins the infrastructure.

  • GovRAMP

    US state & local government cloud authorization (formerly StateRAMP).

    How it helps — Public-sector-grade assurance.

  • TX-RAMP

    The Texas Risk & Authorization Management Program.

    How it helps — Meets Texas public-sector security requirements.

  • KRITIS / NIS-2

    German & EU critical-infrastructure operator obligations, certified per §8a BSIG.

    How it helps — Infrastructure held to critical-service resilience and security duties.

  • ENS

    Spain's Esquema Nacional de Seguridad (National Security Framework).

    How it helps — Meets the Spanish national security framework.

  • IRAP

    Australia's Information Security Registered Assessors Program.

    How it helps — Australian government-grade security assessment.

  • ISMAP

    Japan's government cloud security assessment program.

    How it helps — Japanese public-sector-grade assurance.

Reliability, quality & sustainability

  • ISO 22301

    The standard for business continuity management.

    How it helps — Providers plan for disruptions, so the platform stays available through incidents.

  • ISO/IEC 20000-1

    The IT service management standard.

    How it helps — Mature, repeatable operations behind the services we depend on.

  • ISO 9001

    The quality management system standard.

    How it helps — Consistent, documented service quality.

  • Uptime Tier

    Uptime Institute Tier certification for data-center design, facility and operations.

    How it helps — Physical infrastructure engineered for high availability.

  • Climate Neutral DC Pact

    A European pledge for carbon-neutral data centers by 2030.

    How it helps — Greener hosting for your workloads.

  • TPN

    Trusted Partner Network (Blue Shield), aligned to MPA content-security best practices.

    How it helps — Media and content stored to film-industry security standards.

  • HECVAT

    The Higher-Education Community Vendor Assessment Tool.

    How it helps — Vetted for use by universities and research institutions.

  • VPAT / Section 508

    A Voluntary Product Accessibility Template against Section 508 guidelines.

    How it helps — Services remain accessible to users with disabilities.

Provider data-protection practices

  • TLS 1.3

    The latest transport-layer encryption protocol.

    How it helps — Data in transit is strongly encrypted everywhere it crosses a network.

  • Encryption at rest

    Stored data is encrypted, with row-level encryption for sensitive tables.

    How it helps — Stored data is unreadable if storage media are ever compromised.

  • Point-in-time backups

    30-day retention, globally replicated backups.

    How it helps — Recoverability against data loss or a regional outage.

  • Annual pen-testing

    Third-party offensive security testing at least annually.

    How it helps — Vulnerabilities are found and fixed proactively.

Certifications are held by the independent providers that operate each location — not by askFinz — and are subject to their own audit cycles. We track them as part of our vendor due-diligence.

Questions about data residency or a specific certificate? Read our security overview or get in touch.

Trust center