In this section, you can find a summary of our policies with frequently asked information. Our Information Security Management System (ISMS) is ISO/IEC 27001:2022 certified. See Compliance & Governance for full certification details.
Table of Contents
Architecture
Modern Cloud Architecture
Warren's infrastructure is built on AWS eu-central-1 (Frankfurt) with security-first principles.
Data Residency & Sovereignty
- All member, pension and financial data is hosted within the European Union
- A limited number of operational subprocessors (e.g. authentication, error monitoring, communications) are based outside the EU; all such transfers are governed by EU Standard Contractual Clauses. See our subprocessor list for details.
- Compliance with EU data protection and data residency requirements
Infrastructure Security Controls
- Multi-environment Isolation: Strict separation between production and lower environments (dev/staging) using separate AWS accounts.
- Infrastructure as Code: All infrastructure managed through versioned, auditable code
- Encryption Standards: AES-256 encryption at rest, TLS 1.3 for data in transit
Security Monitoring & Incident Response
- 24/7 Security Monitoring: Continuous monitoring of all systems and data access
- Threat Detection: Advanced threat detection with automated response capabilities
- Incident Response Plan: Documented procedures for security incident management
- Regular Security Assessments: Annual third-party penetration testing and vulnerability assessments; a summary is available to customers on request
AI Providers