Security & Compliance

Vertraut von den weltweit
führenden Finanzinstituten

Eine Konversationsebene, die Banken,
Vermögensverwalter und ihre Kunden verbindet

Cloud offeringsBusiness continuityIAM & securityCertificationsCompliance center
Unsere Mission

Innovation, damit jedes digitale
Gespräch zählt

Choose the infrastructure that fits your sovereignty requirements, regulatory environment, and operational model. All three options are covered by Unblu's own certifications and 24/7 operations.

Google Cloud Platform

Unblu Financial
Cloud on GCP

Multi-region deployment. Clients select their failover region to meet geofencing requirements. Covered by Unblu's ISO 27001 and SOC 2 Type 2 certifications.

ISO 27001
SOC 2 Type 2
Client-selectable failover
Multi-region
Swiss Open Telekom Cloud

Unblu Swiss
Sovereign Cloud

Hosted by T-Systems Schweiz AG in two Swiss data centres - Zollikofen and Bern. Designed for institutions requiring full Swiss data sovereignty. Also covered under ISO 27001 and SOC 2 Type 2.

ISO 27001
SOC 2 Type 2
Swiss data sovereignty
Dual-site Swiss DC
IBM Financial Services Cloud

IBM FS Cloud Validated

Purpose-built for regulated financial workloads. Unblu has passed IBM's rigorous security review, with the highest levels of encryption, preventive and compensatory controls, and proactive automated security measures.

FS Validated
AES-256
Regulatory workloads
Automated controls
Branchenfokus

Massgeschneidert für Finanzdienstleister

99.75%
Committed SLA
24h
RPO (regional failover)
3 days
RTO (regional failover)
24/7
Operational 
support

99.75% committed SLA

The Unblu Financial Cloud offers a 99.75% SLA - a legally binding commitment, not a target or objective. This gives clients contractual assurance on the robustness and reliability of our cloud setup, as opposed to a Service-level Objective (SLO) or Service-level Target (SLT).

In-region RPO and RTO

Unblu maintains defined Recovery Point and Recovery Time Objectives within each deployment region, ensuring minimal data loss and rapid restoration in the event of an incident.

Failover region

For GCP deployments, in the event of a full regional failure (all three data centres), the Unblu application can be restored in an alternate region within 3 days, with an RPO of 24 hours. Clients select their backup region to comply with geofencing requirements. For OTC, failover operates between the two Swiss data centre locations in Zollikofen and Bern.

Multi-region availability

Unblu Financial Cloud is available in data centres across Europe, North America, and APAC, with 24/7 operational support from Unblu's cloud operations team.

Ökosystem

Vorintegriert in den Bankensystemen, die Sie bereits nutzen

Unblu ist die einzige Konversationsplattform mit Referenzimplementierungen in den führenden Core-Banking-, Digital-Banking- und Cloud-Ökosystemen.

Zero trust architecture

Unblu operates on a zero-trust model. Our infrastructure is accessible only via managed, specially hardened endpoint devices requiring triple authentication. No implicit trust is granted at any layer of our system.

Data encryption at rest and in transit

All data in the Unblu database and file system is AES-256 encrypted at rest. In transit, we enforce a minimum of TLS 1.2 across all connections.

Hardened, remotely managed endpoints

Cloud operations staff can only access the cloud operations layer via specially controlled and hardened endpoint devices - limiting access to an approved, fully audited set of users and eliminating unmanaged access vectors.

Background-checked staff

All employees working in cloud operations are background screened annually by an independent third-party provider, ensuring ongoing personnel integrity across our operations function.

Regular DR and runbook testing

Unblu maintains robust Disaster Recovery strategies with dedicated runbooks, tested on a regular basis to validate readiness and ensure response procedures remain current and effective.

Annual penetration testing

Our cloud setup is penetration-tested each year by an independent external organisation, with findings reviewed and remediated as part of our continuous security improvement programme.

Kunden

Von den vertrauenswürdigsten Finanzmarken der Welt ausgewählt

Über 170 führende globale Banken und
Vermögensverwaltungen vertrauen Unblu.

ISO 27001:2022

Unblu is ISO 27001 certified for the operation and provisioning of cloud-based software services - the international standard for information security management, requiring systematic identification, assessment, and treatment of information security risks.

SOC 2 Type 2

Our SOC 2 Type 2 report provides independently audited evidence of the controls we apply to protect client data and maintain operational transparency. Covers our GCP and OTC deployments, based on 2017 AICPA Trust Services Criteria.

IBM FS Cloud Validated

Unblu has passed IBM's rigorous security and compliance review for financial services workloads - validating adherence to the industry's most stringent standards, including the highest encryption levels and controls designed for regulated environments.

IRQAO Registered

Unblu's ISO 27001 certification is registered with IRQAO and available for independent verification, providing clients with a transparent, externally accessible record of our certification status.

GCP Platform Certifications

GCP-based deployments benefit from Google Cloud's extensive portfolio of infrastructure-level compliance certifications. Full details are available via Google Cloud's Compliance & Regulations Resource.

GDPR Compliant

Unblu and its affiliates are committed to compliance with Swiss and EU data protection regulations, as well as applicable requirements in other jurisdictions where Unblu operates, including the US and Canada.

Sicherheit & Compliance

Zertifiziert nach den Standards, an denen sich Banken selbst messen

Easy access to the certificates, policies, and audit reports your organisation needs to meet its compliance obligations.

Corporate Compliance

CSR Policy

Unblu's approach to corporate social responsibility, based on ISO 26000:2010. Covers our commitments to people, environment, and the communities we operate in.

Download

Whistleblowing Policy

Ensures all Unblu employees can raise concerns about wrongdoing or malpractice without fear of retaliation, discrimination, or dismissal.

Download

Code of Conduct

Unblu's Business Code of Conduct and Ethics, setting out the standards of behaviour expected across the organisation.

Download
Cloud Information Security

ISMS Information Security Manual

Documents Unblu's Information Security Management System, enabling systematic assessment and treatment of information security risks in line with global best practices.

Request (NDA)

ISO 27001 Certificate

Our current ISO 27001:2022 certificate, available for direct download.

Download

SOC 2 Type 2 Report

Externally audited report covering Unblu's Conversation Platform Services infrastructure, based on 2017 AICPA Trust Services Criteria.

Request (NDA)

ISMS Statement of Applicability

Externally audited report covering Unblu's Conversation Platform Services infrastructure, based on 2017 AICPA Trust Services Criteria.

Request (NDA)

Cloud Privacy Notification

Covers Unblu's compliance with Swiss and EU data protection laws, and applicable requirements in other jurisdictions including the US and Canada.

Download

Cloud Cookie Policy

Details on the essential, technically necessary cookies used by Unblu products.

Download