Security
Your case file may contain merchant agreements, settlement reports, KYC documents and bank details. We treat every byte as if it were our own — and back that up with independent audits.
All customer data is encrypted at rest using AES-256 with keys managed by AWS KMS in EU-hosted hardware security modules (HSMs). Data in transit uses TLS 1.3 with modern cipher suites; we publish strict CAA and HSTS records and score A+ on Qualys SSL Labs. Database backups, document store and message archives are all encrypted with separate keys to limit blast radius.
Multi-factor authentication is supported for every account and enforced for all staff. Internal access follows least-privilege and just-in-time principles — engineers do not have standing access to production data; access is granted per-incident, time-boxed and recorded. Single sign-on (SAML 2.0 / OIDC) is available for clients on our Enterprise plan.
We run on AWS in eu-west-1 (Ireland) and eu-central-1 (Frankfurt). Application workloads are containerised and segregated by environment; production has no inbound SSH; deployments are immutable and reviewed by at least two engineers. The platform auto-scales horizontally and is backed by multi-AZ databases with point-in-time recovery and a documented 4-hour RTO / 1-hour RPO.
24/7 monitoring with centralised structured logging, anomaly detection, and on-call rotation. Security events are triaged by our incident response team within 15 minutes of detection. We tabletop-test our incident plan twice a year and report incidents materially affecting personal data to the Irish Data Protection Commission within 72 hours as required by GDPR Article 33.
Independent SOC 2 Type II audits cover Security, Availability and Confidentiality. Our ISO 27001 certificate is renewed annually by an accredited certification body. Penetration tests are commissioned twice a year from an external CREST-accredited firm; high-severity findings are remediated within 30 days. Recent SOC 2 and pentest summaries are available under NDA to prospective clients — request via security@unblockfunds.com.
We welcome reports from the security research community. If you believe you've found a security issue, please email security@unblockfunds.com (PGP key on request) with a clear description and reproduction steps. We commit to:
Out of scope: physical attacks, social engineering of staff, denial-of-service, and any testing that degrades service for other users.
Security is shared. Please use a strong, unique password, enable MFA, keep your recovery email up to date, and limit user accounts to people who genuinely need access. Report a lost device or suspected compromise immediately by emailing security@unblockfunds.com.
We maintain a public list of subprocessors (cloud hosting, email delivery, identity verification, error monitoring, support tooling) with the data they process and the country in which it is processed. We notify customers at least 30 days before adding or replacing a subprocessor. Request the current list from dpo@unblockfunds.com.
Procurement, vendor risk and InfoSec teams can request our SOC 2 report, ISO 27001 certificate, penetration-test executive summary, and Data Processing Addendum.
Request documentation