€18.4M recovered in 2025 · 1,200+ cases closed · ISO 27001 secure

Security

Defence-in-depth, by default.

Your case file may contain merchant agreements, settlement reports, KYC documents and bank details. We treat every byte as if it were our own — and back that up with independent audits.

ISO/IEC 27001
Certified ISMS
SOC 2 Type II
Audited annually
GDPR
EU data residency
PCI DSS SAQ-A
Card-data scoped out

Encryption

All customer data is encrypted at rest using AES-256 with keys managed by AWS KMS in EU-hosted hardware security modules (HSMs). Data in transit uses TLS 1.3 with modern cipher suites; we publish strict CAA and HSTS records and score A+ on Qualys SSL Labs. Database backups, document store and message archives are all encrypted with separate keys to limit blast radius.

Authentication & access

Multi-factor authentication is supported for every account and enforced for all staff. Internal access follows least-privilege and just-in-time principles — engineers do not have standing access to production data; access is granted per-incident, time-boxed and recorded. Single sign-on (SAML 2.0 / OIDC) is available for clients on our Enterprise plan.

Infrastructure

We run on AWS in eu-west-1 (Ireland) and eu-central-1 (Frankfurt). Application workloads are containerised and segregated by environment; production has no inbound SSH; deployments are immutable and reviewed by at least two engineers. The platform auto-scales horizontally and is backed by multi-AZ databases with point-in-time recovery and a documented 4-hour RTO / 1-hour RPO.

Monitoring & response

24/7 monitoring with centralised structured logging, anomaly detection, and on-call rotation. Security events are triaged by our incident response team within 15 minutes of detection. We tabletop-test our incident plan twice a year and report incidents materially affecting personal data to the Irish Data Protection Commission within 72 hours as required by GDPR Article 33.

Audits & assurance

Independent SOC 2 Type II audits cover Security, Availability and Confidentiality. Our ISO 27001 certificate is renewed annually by an accredited certification body. Penetration tests are commissioned twice a year from an external CREST-accredited firm; high-severity findings are remediated within 30 days. Recent SOC 2 and pentest summaries are available under NDA to prospective clients — request via security@unblockfunds.com.

Vulnerability disclosure

We welcome reports from the security research community. If you believe you've found a security issue, please email security@unblockfunds.com (PGP key on request) with a clear description and reproduction steps. We commit to:

  • Acknowledge your report within 2 business days.
  • Provide a triage decision within 5 business days.
  • Not pursue legal action against good-faith researchers who follow this policy.
  • Credit reporters in our Security Hall of Fame (with consent).

Out of scope: physical attacks, social engineering of staff, denial-of-service, and any testing that degrades service for other users.

Customer responsibilities

Security is shared. Please use a strong, unique password, enable MFA, keep your recovery email up to date, and limit user accounts to people who genuinely need access. Report a lost device or suspected compromise immediately by emailing security@unblockfunds.com.

Subprocessors

We maintain a public list of subprocessors (cloud hosting, email delivery, identity verification, error monitoring, support tooling) with the data they process and the country in which it is processed. We notify customers at least 30 days before adding or replacing a subprocessor. Request the current list from dpo@unblockfunds.com.

Need security documentation?

Procurement, vendor risk and InfoSec teams can request our SOC 2 report, ISO 27001 certificate, penetration-test executive summary, and Data Processing Addendum.

Request documentation