Security & Compliance

Your data, protected

At RocketFin, security is not an option. Every piece of data you entrust to us benefits from enterprise-grade protection.

Confidential & Secure Data

Hosted in France with Scaleway

100% GDPR

ISO 27001 (In Progress)

Enterprise-grade security

Six pillars that protect your financial data 24/7

End-to-End Encryption

TLS 1.3 for all connections, AES-256 at rest. Encryption keys automatically rotated every 90 days.

  • TLS 1.3 with Perfect Forward Secrecy
  • AES-256-GCM for data at rest
  • Automatic key rotation
  • HSM (Hardware Security Module) for critical keys

Sovereign Hosting

100% French infrastructure with Scaleway. Certified datacenters in Paris and Amsterdam (EU).

  • Scaleway Tier III+ certified datacenters
  • Geographic redundancy France/EU
  • Data never leaves the EU
  • 99.99% uptime SLA

GDPR Compliance

100% GDPR compliant. Strict data management policies and clearly defined user rights.

  • Data processing register maintained
  • Privacy by design
  • Data portability guaranteed
  • Right to erasure implemented

Data Isolation

Complete tenant isolation. Your data is never shared or crossed with another client.

  • Physical isolation per tenant
  • Dedicated encrypted databases
  • Strict access controls
  • Complete audit trail

Access & Authentication

Multi-factor authentication, role-based access management, and complete session audit.

  • MFA enforced for all accounts
  • RBAC (Role-Based Access Control)
  • Complete access logs
  • Automatic session timeout

ISO 27001 (In Progress)

ISO 27001 certification in progress. SOC 2 Type II and HDS evaluations planned.

  • ISO 27001 audit in progress (ETA Q4 2026)
  • SOC 2 Type II planned during 2027
  • HDS (Health Data) planned during 2027
  • Penetration test every 6 months

Questions about our security?

Our team is available to answer all your questions