Skip to content
vincu

Security & compliance

The boring parts, done properly.

Banks don't buy promises. Here is how Vincu actually handles your data, your access model and your auditors.

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with keys held in a managed key-management service, rotated on schedule and never stored alongside the data. Documents exchanged through Vincu Vault never travel over email.

Access control

Role-based access control throughout: staff see the cases, documents and actions their role allows, and nothing else. Sessions expire on a hard limit; sensitive actions are re-verified.

Auditability

Every decision, document movement, status change and message is written to an immutable audit log with actor, timestamp and context. Security events are logged with IP-protecting hashing.

Data residency & hosting

Vincu runs on AWS infrastructure in EU regions, with Frankfurt as the primary region. Each bank runs its own single-tenant deployment with bank-specific configuration, and data — including AI processing — stays inside the EU. On-premise deployment is available for institutions that require it.

Regulatory alignment

Built for EU-regulated banking workloads: GDPR-aligned data handling, consent-tracked credit-registry queries and explainable, logged credit decisions.

Certifications

We are preparing for SOC 2 certification, and Vincu's controls — access management, encryption, audit logging, change management — are built to that standard today. We share our current certification status and audit documentation openly during any security review.

AI, governed

A note on AI in credit decisions

Vincu Decision assists; it doesn't decide alone. Every AI-assisted analysis is presented with its reasoning, reviewed by your staff, and logged — designed so you can explain any decision to a customer, a regulator or an auditor.

Have your security team grill ours.

Bring your questionnaire. We'll answer it line by line.