Security & compliance
Security is the product.
A platform that holds the full financial picture of families and their advisors has no room for “trust us”. So we show it. Live.
ISO 27001 certified · incl. 27017 & 27018Infrastructure & AI in the Netherlands
Certifications & frameworks
ISO 27001:2022 certified
Including the ISO 27017 and ISO 27018 extensions.
One certification, extended to the full stack: ISO/IEC 27001:2022 for the information security management system, with the ISO/IEC 27017:2015 extension for cloud security and the ISO/IEC 27018:2019 extension for personal data in the cloud. We went for the full standard because the financial data we hold deserves it, with zero findings in every category: no major or minor non-conformities, no observations.
- Certification body
- Prescient Security
- Standards
- ISO/IEC 27001:2022 · 27017:2015 · 27018:2019
- Scope
- The information security management system of Bonafi B.V., supporting the design, development, operation and support of Bonafi’s AI-first software platform for wealth management, including the client-data database, the AI processing pipeline and supporting SaaS tooling, on infrastructure hosted on Google Cloud.
- Initial audit
- Stage 1 on 5 June 2026 · Stage 2 from 15 to 19 June 2026
- Findings
- Zero non-conformities, zero observations
From starting the programme to certification took two months. Not because the audit was rushed, but because there was little to retrofit: Bonafi was built to these standards before it was measured against them. The controls stay under continuous monitoring in our Trust Center, and you can request the certification details via info@bonafi.ai.
GDPR compliant
There is no such thing as “GDPR certified”: no certification scheme exists, so we will not claim one. Compliance is something you check, not something we badge. These are the pieces:
- Our privacy policy, with concrete retention periods and every processor named.
- A data processing agreement with every client.
- The sub-processor list with locations, kept current in the Trust Center.
- EU data residency, down to the region.
Client data never leaves the European Union.
Data residency
The Netherlands. Including the AI.
Infrastructure and AI run in one place: Eemshaven, the Netherlands, on Google Cloud, region europe-west4. Your documents are read there, not sent elsewhere. No provider may train on them; that is contractual, not a preference.
Your documents
Fund reports · deeds · statements
The Netherlands · Eemshaven · europe-west4
Compute & storage
Encrypted at rest
AI, reading documents
No-training commitments
Everything happens inside this boundary
Your overview
Every figure traceable to its source
Client data never leaves the European Union
Access & sub-processors
Who touches what.
Two kinds of “who”: the people you give access to, and the companies that process data for the platform. Both belong in the open.
People · access you control
You and your family
Everything you hold
It is your record. You decide who else sees any of it.
Advisors you invite
Exactly the slice you choose, per asset
Your accountant, notary or tax advisor sees what they need for their work, and nothing more.
Relationship managers, for offices
Their own families only
Scoped by mandate, with a clean portal per client.
Bonafi itself
None by default
Only your dedicated account manager can access your environment, and only with your approval. Logged, like everything else.
Role-based, per person, configured by you · every action logged, and the log itself is a source
Companies · sub-processors of the platform
Google Cloud
Infrastructure & AI · Eemshaven, the Netherlands (europe-west4)
Compute, storage and the AI that reads documents, inside one Dutch region. No provider may train on your documents; that is contractual.
PlanetScale
Database · European Union
Managed database for application data and client records, encrypted at rest and in transit, deployed in an EU region.
Vanta
Compliance monitoring · EU environment
Continuous control monitoring behind our Trust Center.
Microsoft 365
Document management · European Union
Internal business documents.
The complete, always-current list lives in our Trust Center, with every provider named.
Follow our controls live.
Our Trust Center shows the real-time status of our security controls, our sub-processors, and our policies. No snapshots, no claims. The current state, always.
How we build
Dutch by architecture.
Infrastructure and AI inference both run on Google Cloud in Eemshaven. No-training commitments from every provider.
Encryption everywhere.
In transit and at rest, on every layer.
Access follows responsibility.
Role-based access for clients, advisors and relationship managers, with SSO sign-in. Every action logged.
Humans in the loop.
No figure becomes part of the record without review. The approval queue is architecture, not a feature.
Common questions
Is Bonafi licensed under the Dutch Financial Supervision Act (Wft)?
Bonafi is a software platform: it provides insight and administration, and does not manage assets, execute transactions or give investment advice. The platform provides the foundation; your advisor keeps the judgement.
Is my data used to train AI models?
No. Every AI provider we use is bound by a no-training commitment: your documents never train anyone's models, ours or theirs. What does improve is extraction: your corrections are stored as structured feedback and reused, for you and, in non-personal form, across clients. Never on personal data.
Who can see my data?
Access follows responsibility: role-based, per person, configured by you. Every action is logged, and the log itself is a source.
What happens to our data if we leave?
It is returned or deleted in line with your agreement, and your data can be exported to you directly at any time. That holds in every scenario, including the one where Bonafi itself were ever to stop: your records go with you, not with us.
Can Bonafi move my money?
No. Bonafi prepares a transfer through our bank connection layer (Plaid): amount, account and reference, staged and ready. Authorising it happens at your bank, by you. Money out is never automatic.
Do you test your own security, and what if something goes wrong?
Penetration tests are run against the platform, and the controls stay under continuous monitoring in our Trust Center. If a security incident affects your data, you hear it from us within 48 hours.
Questions about security or compliance?
Get in touchNot ready for a demo? Join the waitlist