Fintech.
Answers for your auditors.
Run regulated services in Frankfurt with a provider you can explain in a risk review: German company, EU data, no US parent.
What changes.
From open questions to evidence.
Procurement and regulators question where data lives
Frankfurt, under German and EU law
A US parent company creates CLOUD Act exposure
enum GmbH has no US entity in its structure
Records must be kept unchanged for years
Object Lock keeps objects immutable for the retention you set
Environments must be separated for your risk model
Separate clusters and projects for production, staging and audit
How fintech teams land on enum.
From risk review to production.
Map residency and scope
Decide which workloads and data must stay in the EU. Frankfurt is enum's production region.
Separate environments
Each Kubernetes cluster has its own control plane. Split environments the way your risk model requires.
Lock what must not change
Use Object Lock for retention-sensitive records, and ship logs to your existing SIEM.
What you run it on.
enum Kubernetes Engine
Upstream Kubernetes with a highly available control plane per cluster.
Object Storage
S3-compatible storage with Object Lock for records that must not change.
Networking
Private networking and load balancing to keep regulated services apart.
Questions.
About fintech on enum.
Does enum help with DORA and NIS2?
enum covers the provider side: a German company, data in Frankfurt and no US subprocessors in the data path. Your own policies and oversight stay with you.
Is customer data subject to the US CLOUD Act?
No. enum GmbH is a German company with no US entity in its structure, so the CLOUD Act does not apply.
Can we keep production and audit trails separate?
Yes. Use separate clusters and projects per environment, and Object Lock buckets for records that must not change.
Which certifications are in place?
The Frankfurt data center is certified to ISO 27001 and EN 50600; those certificates belong to the facility operator. enum's own ISO 27001 certification is in progress, with a target of Q4 2026.
Running regulated workloads?
Walk us through your risk model.
We answer the provider questions in your review, with engineers in the room.