ISO 27001-aligned

Security Overview

We protect our infrastructure and your data with industry-leading security standards. Below is a summary of our technical and organizational measures.

01

Data Transport

All traffic to and from our services is encrypted with TLS 1.3. HSTS with preload enforces secure connections and prevents downgrade attacks.

  • TLS 1.3 — latest encryption protocol
  • HSTS preload — always-force HTTPS
  • Perfect Forward Secrecy
  • HTTP/2 and HTTP/3 (QUIC) support
TLS 1.3
A+
SSL Labs rating
Edge
Cloudflare + Hetzner
EU
02

Infrastructure & Network

Our platform is built on Cloudflare's edge network with Hetzner as backend. All infrastructure is within the EU.

  • Cloudflare — CDN, DDoS protection, WAF (OWASP Top 10)
  • Hetzner — ISO 27001-certified data centers in Germany
  • Anycast network with global edge capacity
  • Rate limiting on API endpoints
  • Automatic DDoS mitigation
03

Application Security

Our website and services are protected with multiple layers of security controls.

  • Content Security Policy — blocks XSS and inline event handlers
  • Cross-Origin-Opener-Policy: same-origin
  • Cross-Origin-Embedder-Policy: credentialless
  • Honeypot — invisible bot protection on contact forms
  • Permissions-Policy — restricts API access (camera, mic, geo)
CSP
Nonce-based
COOPCOEPCORP
DNSSEC
CAA • RRSIG
DSA
04

DNS Security

The domain is protected with multiple DNS security layers.

  • DNSSEC — signed DNS responses prevent cache poisoning
  • CAA records — restricts certificate authorities to Google Trust Services, Let's Encrypt and DigiCert
  • Cloudflare DNS — redundant anycast nameservers
05

Email Security

We protect our email domain against spoofing and phishing.

  • SPF — authorized sending servers
  • DKIM — 2048-bit signing of outbound email
  • DMARC — p=reject with reporting
  • Brevo (France) — GDPR-compliant email delivery
DMARC
p=reject
SPFDKIMDMARC
06

Compliance & Certifications

Our practices and controls are designed to meet the following standards:

GDPR — full compliance for all EU/EEA personal data processing

ISO 27001:2022 — mapped against all 93 Annex A controls

SOC 2 Type II — Cloudflare and Hetzner are SOC 2 certified

DPA — Data Processing Agreements with all subprocessors

Incident Response — P1 within 15 min, GDPR breach notification within 72 hours

Subprocessors & DPAs

Cloudflare — CDN, WAF, DNS, SSL (US, EU-US DPF)
Hetzner — cloud server (Germany, ISO 27001)
Brevo — email (France, ISO 27001)
07

Report a Security Issue

We welcome responsible disclosure of security issues. Contact us at:

Contact: mailto:hello@fxg.se
Preferred-Languages: sv, en
Policy: https://fxg.se/privacy/
Canonical: https://fxg.se/.well-known/security.txt
08

Self-Certification — ISO 27001-Aligned

FX Group is not formally ISO 27001 certified, but we operate a complete ISMS aligned to all 93 ISO 27001:2022 Annex A controls. Our security posture has been independently scored at 91/100 A+ by SiteSecurityScore — well above industry average. This is called "ISO 27001-aligned" or "ISO 27001-informed" and is a common approach for small businesses that maintain the same security level without the certification cost.

Our policies and ISMS documents are available for review:

Subprocessor TOMs
Statement of Applicability (all 93 controls)
Incident Response Runbook

Contact us if you need access to the full documentation for your own review or vendor assessment.

Want to learn more?

Contact us if you have questions about our security or need a Data Processing Agreement.