Security Overview
We protect our infrastructure and your data with industry-leading security standards. Below is a summary of our technical and organizational measures.
Data Transport
All traffic to and from our services is encrypted with TLS 1.3. HSTS with preload enforces secure connections and prevents downgrade attacks.
- TLS 1.3 — latest encryption protocol
- HSTS preload — always-force HTTPS
- Perfect Forward Secrecy
- HTTP/2 and HTTP/3 (QUIC) support
Infrastructure & Network
Our platform is built on Cloudflare's edge network with Hetzner as backend. All infrastructure is within the EU.
- Cloudflare — CDN, DDoS protection, WAF (OWASP Top 10)
- Hetzner — ISO 27001-certified data centers in Germany
- Anycast network with global edge capacity
- Rate limiting on API endpoints
- Automatic DDoS mitigation
Application Security
Our website and services are protected with multiple layers of security controls.
- Content Security Policy — blocks XSS and inline event handlers
- Cross-Origin-Opener-Policy: same-origin
- Cross-Origin-Embedder-Policy: credentialless
- Honeypot — invisible bot protection on contact forms
- Permissions-Policy — restricts API access (camera, mic, geo)
DNS Security
The domain is protected with multiple DNS security layers.
- DNSSEC — signed DNS responses prevent cache poisoning
- CAA records — restricts certificate authorities to Google Trust Services, Let's Encrypt and DigiCert
- Cloudflare DNS — redundant anycast nameservers
Email Security
We protect our email domain against spoofing and phishing.
- SPF — authorized sending servers
- DKIM — 2048-bit signing of outbound email
- DMARC — p=reject with reporting
- Brevo (France) — GDPR-compliant email delivery
Compliance & Certifications
Our practices and controls are designed to meet the following standards:
GDPR — full compliance for all EU/EEA personal data processing
ISO 27001:2022 — mapped against all 93 Annex A controls
SOC 2 Type II — Cloudflare and Hetzner are SOC 2 certified
DPA — Data Processing Agreements with all subprocessors
Incident Response — P1 within 15 min, GDPR breach notification within 72 hours
Subprocessors & DPAs
Report a Security Issue
We welcome responsible disclosure of security issues. Contact us at:
Self-Certification — ISO 27001-Aligned
FX Group is not formally ISO 27001 certified, but we operate a complete ISMS aligned to all 93 ISO 27001:2022 Annex A controls. Our security posture has been independently scored at 91/100 A+ by SiteSecurityScore — well above industry average. This is called "ISO 27001-aligned" or "ISO 27001-informed" and is a common approach for small businesses that maintain the same security level without the certification cost.
Our policies and ISMS documents are available for review:
Contact us if you need access to the full documentation for your own review or vendor assessment.
Want to learn more?
Contact us if you have questions about our security or need a Data Processing Agreement.