---
canonical: https://enum.co/industry/fintech
locale: en
---

# Fintech. Answers for your auditors.

Fintechs and financial services run regulated workloads on enum in Frankfurt: managed Kubernetes, S3-compatible object storage with Object Lock and private networking, operated by a German company with no US parent.

Run regulated services in Frankfurt with a provider you can explain in a risk review: German company, EU data, no US parent.

## What changes. From open questions to evidence.

- Procurement and regulators question where data lives → Frankfurt, under German and EU law
- A US parent company creates CLOUD Act exposure → enum GmbH has no US entity in its structure
- Records must be kept unchanged for years → Object Lock keeps objects immutable for the retention you set
- Environments must be separated for your risk model → Separate clusters and projects for production, staging and audit

## How fintech teams land on enum. From risk review to production.

1. **Map residency and scope**: Decide which workloads and data must stay in the EU. Frankfurt is enum's production region.
2. **Separate environments**: Each Kubernetes cluster has its own control plane. Split environments the way your risk model requires.
3. **Lock what must not change**: Use Object Lock for retention-sensitive records, and ship logs to your existing SIEM.

## What you run it on.

- [enum Kubernetes Engine](https://enum.co/kubernetes-engine): Upstream Kubernetes with a highly available control plane per cluster.
- [Object Storage](https://enum.co/object-storage): S3-compatible storage with Object Lock for records that must not change.
- [Networking](https://enum.co/networking): Private networking and load balancing to keep regulated services apart.

NIS2 · DORA: How a European provider fits the third-party and supply-chain rules.

## Questions. About fintech on enum.

### Does enum help with DORA and NIS2?

enum covers the provider side: a German company, data in Frankfurt and no US subprocessors in the data path. Your own policies and oversight stay with you.

### Is customer data subject to the US CLOUD Act?

No. enum GmbH is a German company with no US entity in its structure, so the CLOUD Act does not apply.

### Can we keep production and audit trails separate?

Yes. Use separate clusters and projects per environment, and Object Lock buckets for records that must not change.

### Which certifications are in place?

The Frankfurt data center is certified to ISO 27001 and EN 50600; those certificates belong to the facility operator. enum's own ISO 27001 certification is in progress, with a target of Q4 2026.
