Skip to main content
Security & compliance

The page your tender response will cite.

Enterprise buyers and city tenders need a URL, not a promise. Here it is: how your data is hosted, encrypted, and isolated, how the platform holds up under failure, and how to get the full documentation pack for your security review.

EU
Data residency
AWS Frankfurt (eu-central-1)
Zero
Card details stored
Handled by PCI DSS-certified providers
24/7
On-call incident response
Formal SANS-based response plan
Daily
Encrypted backups
15-day retention, point-in-time recovery
How it is built

Secure by default, not by add-on.

The controls a security review looks for are how the platform is built, not a paid tier on top of it. Every operator on Wunder Mobility runs on the same foundation.

EU hosting and data residency

Wunder Mobility runs 100% on AWS in Frankfurt (eu-central-1). Your data stays in the EU, on a cloud foundation that is itself SOC 2 Type II and ISO 27001 certified.

Encryption in transit and at rest

TLS 1.2 and above for everything in transit. Data at rest is encrypted with AWS KMS keys that rotate automatically.

Isolation between operators

Each operator runs in a dedicated deployment with its own database, storage, and access roles. Your data is never mixed into a shared table with another operator’s.

Access and authentication

Sign-in uses OAuth2 and OpenID Connect with short-lived, rotating tokens. Role-based permissions and audit trails cover the back office, and single sign-on is supported.

Payments without card data

Wunder Mobility never stores card details. Payments run through PCI DSS-certified providers (Stripe, Adyen, Checkout.com), and our own scope is PCI DSS SAQ A.

Secure development and testing

Infrastructure is defined as code and deployed through GitOps. Every change passes automated security and container-image scans in CI, and the platform is penetration-tested by independent third parties.

Resilience by design

What happens when something goes wrong.

Availability and recovery are the questions an evaluator asks next. Here is how the platform answers the four that matter most.

A data-centre zone fails
Your fleet could drop offline
Multi-AZ deployment behind managed load balancing fails over automatically, with no single instance as a point of failure
A release ships a bug
A broken change reaches production
Every change is automatically security-scanned and tested before it ships, so a bad release is caught early and rolled back fast
Data is lost or corrupted
Bookings and history disappear
Daily encrypted snapshots, 15-day retention, and point-in-time recovery restore data to any second in the window
A security incident occurs
Data and uptime are exposed
A 24/7 on-call rotation and a formal, SANS-based incident response plan with defined SLAs take over
Data protection

GDPR-native, EU by default.

Data protection is built in for an EU operator, from where data sits to the paperwork your legal team needs to sign.

Data Processing Agreement

A GDPR-compliant DPA is available on request, with processing records and EU data residency built in.

Vetted subprocessors

Every data processor is selected for its compliance posture, with a DPA executed with each one. An external Data Protection Office backs our GDPR program.

Deletion workflows

Data deletion workflows help you meet the erasure and data-rights obligations GDPR places on you as the controller.

Certifications and documentation

Everything your security review needs.

The platform runs on a certified cloud foundation, and we keep a security self-assessment ready to share, so your team can map it against your own questionnaire.

Certified cloud foundation

The platform runs on AWS infrastructure that holds SOC 2 Type II and ISO 27001 certifications, with EU data residency in Frankfurt.

Mapped to the standards

Our security self-assessment maps the platform to PCI DSS v4.0 and ISO 27001:2022 controls, so your team can line it up against your own questionnaire.

Ready for your review

Request the full pack: the self-assessment, the DPA, PCI DSS SAQ A, and answered security questionnaires.

Request the pack →
Common questions

The answers your evaluators ask for.

Where is our data stored?

All data is stored in the EU, in AWS’s Frankfurt region (eu-central-1). A Data Processing Agreement is available on request.

Do you store our riders’ card details?

No. Card data is handled entirely by PCI DSS-certified payment providers (Stripe, Adyen, Checkout.com). Wunder Mobility’s own PCI scope is SAQ A, and no card details are stored on our servers.

How is our data isolated from other operators?

Every operator runs in a dedicated deployment with its own database, storage, and access roles. Your data is never mixed into a shared table with another operator’s.

Do you run penetration tests?

Yes. The platform is tested by independent third parties on a regular basis, alongside automated security and image scanning in the deployment pipeline. We can also coordinate an annual external penetration test run by your own security team, with agreed remediation timelines for critical and high findings.

What happens if there is an incident?

A 24/7 on-call rotation monitors production, backed by a formal, SANS-based incident response plan and defined SLAs. Full-stack observability and automated alerting catch anomalies before they reach your riders.

How often is our data backed up?

Daily automated, encrypted snapshots are retained for 15 days, with continuous point-in-time recovery, so data can be restored to any second within the retention window.

Can we run our own security review?

Yes. Request the documentation pack for our security self-assessment (mapped to PCI DSS v4.0 and ISO 27001:2022 controls), the DPA, PCI DSS SAQ A, and answers to your security questionnaire.

Request the security documentation pack.

Everything your security review or tender annex needs, in one response: the self-assessment, the DPA, and PCI DSS SAQ A.

We use cookies for analytics and marketing. Nothing tracks you until you choose.