The page your tender response will cite.
Enterprise buyers and city tenders need a URL, not a promise. Here it is: how your data is hosted, encrypted, and isolated, how the platform holds up under failure, and how to get the full documentation pack for your security review.
Secure by default, not by add-on.
The controls a security review looks for are how the platform is built, not a paid tier on top of it. Every operator on Wunder Mobility runs on the same foundation.
EU hosting and data residency
Wunder Mobility runs 100% on AWS in Frankfurt (eu-central-1). Your data stays in the EU, on a cloud foundation that is itself SOC 2 Type II and ISO 27001 certified.
Encryption in transit and at rest
TLS 1.2 and above for everything in transit. Data at rest is encrypted with AWS KMS keys that rotate automatically.
Isolation between operators
Each operator runs in a dedicated deployment with its own database, storage, and access roles. Your data is never mixed into a shared table with another operator’s.
Access and authentication
Sign-in uses OAuth2 and OpenID Connect with short-lived, rotating tokens. Role-based permissions and audit trails cover the back office, and single sign-on is supported.
Payments without card data
Wunder Mobility never stores card details. Payments run through PCI DSS-certified providers (Stripe, Adyen, Checkout.com), and our own scope is PCI DSS SAQ A.
Secure development and testing
Infrastructure is defined as code and deployed through GitOps. Every change passes automated security and container-image scans in CI, and the platform is penetration-tested by independent third parties.
What happens when something goes wrong.
Availability and recovery are the questions an evaluator asks next. Here is how the platform answers the four that matter most.
GDPR-native, EU by default.
Data protection is built in for an EU operator, from where data sits to the paperwork your legal team needs to sign.
Data Processing Agreement
A GDPR-compliant DPA is available on request, with processing records and EU data residency built in.
Vetted subprocessors
Every data processor is selected for its compliance posture, with a DPA executed with each one. An external Data Protection Office backs our GDPR program.
Deletion workflows
Data deletion workflows help you meet the erasure and data-rights obligations GDPR places on you as the controller.
Everything your security review needs.
The platform runs on a certified cloud foundation, and we keep a security self-assessment ready to share, so your team can map it against your own questionnaire.
Certified cloud foundation
The platform runs on AWS infrastructure that holds SOC 2 Type II and ISO 27001 certifications, with EU data residency in Frankfurt.
Mapped to the standards
Our security self-assessment maps the platform to PCI DSS v4.0 and ISO 27001:2022 controls, so your team can line it up against your own questionnaire.
Ready for your review
Request the full pack: the self-assessment, the DPA, PCI DSS SAQ A, and answered security questionnaires.
Request the pack →The answers your evaluators ask for.
Where is our data stored?
All data is stored in the EU, in AWS’s Frankfurt region (eu-central-1). A Data Processing Agreement is available on request.
Do you store our riders’ card details?
No. Card data is handled entirely by PCI DSS-certified payment providers (Stripe, Adyen, Checkout.com). Wunder Mobility’s own PCI scope is SAQ A, and no card details are stored on our servers.
How is our data isolated from other operators?
Every operator runs in a dedicated deployment with its own database, storage, and access roles. Your data is never mixed into a shared table with another operator’s.
Do you run penetration tests?
Yes. The platform is tested by independent third parties on a regular basis, alongside automated security and image scanning in the deployment pipeline. We can also coordinate an annual external penetration test run by your own security team, with agreed remediation timelines for critical and high findings.
What happens if there is an incident?
A 24/7 on-call rotation monitors production, backed by a formal, SANS-based incident response plan and defined SLAs. Full-stack observability and automated alerting catch anomalies before they reach your riders.
How often is our data backed up?
Daily automated, encrypted snapshots are retained for 15 days, with continuous point-in-time recovery, so data can be restored to any second within the retention window.
Can we run our own security review?
Yes. Request the documentation pack for our security self-assessment (mapped to PCI DSS v4.0 and ISO 27001:2022 controls), the DPA, PCI DSS SAQ A, and answers to your security questionnaire.
Request the security documentation pack.
Everything your security review or tender annex needs, in one response: the self-assessment, the DPA, and PCI DSS SAQ A.