Company

Security

At Cobase, security is embedded in every layer of our platform and operations. From user authentication to system architecture, from secure bank connectivity to data encryption, we safeguard your financial data and ensure compliance with regulations like the GDPR. Our approach is built on certified frameworks, robust processes, and continuous monitoring — giving treasury teams peace of mind and control.

security

Trust through layered security

Cobase’s layered security model — combining robust internal controls, strong external certifications, and GDPR-compliant data protection — ensures that your operations remain secure, reliable, and compliant at all times.
Internal Controls

Cobase operates an Information Security Management System (ISMS) aligned with ISO 27001, ensuring strong governance and continuous improvement. Policies and processes are documented, regularly audited, and updated to reflect evolving threats and requirements. Access controls are implemented via Role-Based Access Control (RBAC), ensuring that users can only access what they need.

User Authentication

Cobase enforces Multi-Factor Authentication (MFA) for all users, with support for hardware tokens and mobile devices. Authentication is secured with strong cryptographic standards, ensuring that only authorized users can access the platform and execute sensitive actions like payments.

Data Protection & Encryption

Data is encrypted both at rest and in transit using industry-accepted protocols (AES, TLS, SSH, and RSA). Cobase ensures that customer data is processed and stored in secure Microsoft Azure data centers located in the EU (Netherlands and Ireland), providing strong data residency and compliance with GDPR requirements

Certificate Management

Cobase manages all digital certificates required for secure bank and ERP connections, including those used in SFTP, EBICS, and API communications. Certificate lifecycles (issuance, renewal, and revocation) are managed automatically by Cobase, eliminating manual maintenance and reducing the risk of expired or misconfigured certificates.

External Controls & Audits

Cobase is externally certified under ISO 27001, SOC2 Type 2, and ISAE 3402 Type 2 standards. We also undergo regular independent audits, penetration testing, and vulnerability assessments to ensure compliance and operational resilience.

Cobase employs a 24/7 Security Operations Center (SOC) to monitor the platform, detect anomalies, and respond to incidents swiftly. Logs and audit trails are immutable, ensuring full traceability and compliance with regulatory frameworks.

GDPR Compliance

Cobase acts as both a data processor (Activity 1) and an independent data controller (Activity 2) depending on the processing context. We implement data protection measures, Data Processing Agreements, and Privacy Impact Assessments to support our customers’ GDPR compliance requirements. Personal data is stored within the EU, and transfers outside the EU/EEA are handled with appropriate safeguards, such as Standard Contractual Clauses.

Key features

ISO 27001, SOC2 Type 2, and ISAE 3402 certifications
Role-Based Access Control with Multi-Factor Authentication
Data encryption at rest and in transit (AES, TLS, RSA, PGP)
Regular independent audits, code reviews, and penetration tests
GDPR-compliant processing with documented Data Processing Agreements
Immutable audit logs capturing all user actions and system events
Dedicated Security Officer and Privacy Officer overseeing governance
24/7 Security Operations Center for continuous monitoring

Frequently asked questions

How are certificates managed?

Cobase fully manages all digital certificates required for secure bank and ERP connectivity, including renewals and revocations.

What security standards does Cobase follow?

Cobase is certified under ISO 27001, SOC2 Type 2, and ISAE 3402 Type 2, ensuring independent verification of our security controls.

Where is customer data stored?

Data is stored in EU-based Microsoft Azure data centers (Netherlands and Ireland), supporting GDPR compliance and data residency.

Can Cobase provide audit logs?

Yes, all user and system actions are logged and can be exported for audits and compliance reviews.

What happens in case of a security incident?

Cobase’s SOC monitors the system 24/7 and acts immediately to investigate and mitigate any incident, with transparent communication to impacted customers as required.

Interested?

Manage all your bank accounts centrally with Cobase

Simplify your cash management and save valuable time. One platform, complete control over all your financial flows.
Image