Third Party Index

Snapshot 19717

Document
Trust center
URL
https://trust.fundapps.co/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
79972 bytes
SHA-256 (raw)
2c0787e46ceca10980b7adee679596b0a5952141be35902d433c860da7e08403
SHA-256 (normalized text)
18adcf6c3bd34697aabec7c659c126882405e8b91cebd6de36956ca9466a1bb6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

FundApps is continuously monitoring its overall security posture.
Compliance
Documentation of our compliance against global standards including certifications, attestations, and audit reports.
Security
Continuous monitoring
Note: If a control is passing all tests, it will be marked as green. If a control has a failed test that was not resolved within the past 3 days, it will be marked yellow.
Data Security
Data Backups
Encryption at Rest
Encryption in Transit
Least-Privileged Policy for Sensitive Data Access
Infrastructure Security
Access to Remote Server Administration Ports Restricted
Change Review Process
Log Management System
Logging/Monitoring
Monitoring Processing Capacity and Usage
Network Security Controls
Root Infrastructure Account Monitored
Organization Security
Access Deprovisioning
Defined Management Roles & Responsibilities
Formal Screening Process
Job Descriptions
Multi-Factor Authentication
On-Call Team
Subprocessors
Shortcut
Ticketing software
Data location: USA
Slack
Communication/messaging tool
Data location: USA
FundApps
The FundApps group is formed of 3 separate entities located in the UK (FundApps Ltd), Singapore (FundApps Pte Ltd) and USA (FundApps Inc) and each will contribute to the provisio...
Data location: United States
ON24
Webcasting and virtual event technology used to host webinars and other interactive demonstrations.
Data location:
Xero
Accounting software for processing invoices and payments from clients and suppliers.
Data location:
Slack
Communication/messaging tool
Data location:
Topics and common questions
21
FundApps maintains a robust security and compliance posture validated through independent third-party audits. We hold ISO 27001 Certification and undergo annual SOC 2 Type 2 assessments. Our infrastructure is hosted entirely within the EU on Amazon Web Services, which holds industry-standard certifications including ISO 9001, ISO 27001, and SOC 1 and 2 certifications. We are committed to aligning our processes with ISO 27001 and the NIST Cyber Security Framework.
We maintain a comprehensive, uniform set of policies and procedures that apply consistently across all clients. This standardised approach ensures operational sustainability, compliance consistency, and reduces the risk of inconsistent security posture across our client base. Our policies are documented, regularly reviewed, and updated to reflect evolving regulatory requirements and industry best practices.
To support efficient and accurate security assessments, we provide clients with access to our trust portal, which contains our SOC 2 Type 2 Report, ISO 27001 Certification, and our policy portal, which all of our security documentation. We encourage clients to self-serve from these resources, as this approach minimises operational complexity and reduces the risk of human error inherent in manual questionnaire completion. Manual Due Diligence Questionnaire processes create significant operational burden and increase the likelihood of transcription errors, inconsistencies, and outdated information. By providing comprehensive, audited documentation through our trust portal, we enable clients to conduct thorough security assessments whilst maintaining the integrity and accuracy of our security posture.
FundApps is assessed annually by independent third-party auditors which provides FundApps with: a SOC 2 Type 2 Report; and an ISO 27001 Certification. Both documents can be requested from FundApps' Trust Center (section Compliance).
FundApps platform is hosted in Amazon Web Services datacentres located in Dublin, Ireland and Frankfurt, Germany.
FundApps' security posture is designed to address the challenges created by models such as Anthropic's Mythos.This includes, but is not limited to, the following controls:
A. Multiple avenues to detect vulnerabilities affecting our platform:
- Static Application Security Testing (SAST) on every code change.
- Weekly Dynamic Application Security Testing (DAST) of the application.
- Bug-bounty program on a reputable platform.
- Annual penetration tests performed by a CREST-accredited third-party.
B. Short SLA's to remediate or mitigate vulnerabilities, prioritised by severity, exploitability and internet exposure, as detailed in our vulnerability management policy (cf. the vulnerability management policy in our policy portal), which is audited and evidenced in our SOC 2 report.
- Critical: ≤2 working days
- High: ≤5 working days
- Medium and
- Low: ≤20 working days
D. A Web Application Firewall to stop incoming malicious traffic, and the ability to apply virtual patching.
E. A SIEM that centralises all security events from our systems operated by our 24/7 SOC.
F. A robust security incident management process which defines how incidents are triaged, contained, assessed, remediated and learned from, as detailed in our security incident response policy (cf. the security incident policy on our policy portal).
Each of these controls is audited and described in our SOC 2 Type 2 Report available in this trust portal.
We now offer Just-In-Time access, a new access control that allows clients to provide FundApps staff with access to their environment for a set period based on the specific context (e.g., incident resolution, investigations). In other words, FundApps staff do not have access to client data unless clients provide it. You can read more about Just-In-Time access here: https://support.fundapps.co/hc/en-us/articles/20198833113885-Just-In-Time-JIT-Access-Management
Additional details
If you're a SteelEye client, please also visit: https://trust.steel-eye.com
Privacy details
Privacy URL