Security
What we do with your data, stated plainly
You are considering sending us statements and ledgers for a regulated business. That deserves specifics rather than a badge wall, including the parts where the honest answer is “not yet”.
Our certification position, without the ambiguity
Finlecy is not currently certified to ISO/IEC 27001 or attested under SOC 2. We are a small company and we would rather say that here than have you discover it in week three of a procurement process. What we do have is the set of controls below, an annual third-party penetration test, and a completed CAIQ-Lite questionnaire we will send on request.
If a certification is a hard requirement for your risk function, tell us early. We will tell you honestly whether our timeline can meet yours rather than running a sales process around it.
01
Where your data lives
- Processing region
- European Union, single region. No processing outside the EU, including for support and diagnostics.
- Sub-processors
- A published list, with thirty days' notice before any addition. Every sub-processor is EU-resident.
- Isolation
- Logical isolation per customer on shared plans. Single-tenant deployment available on Enterprise, or deployment inside your own VPC.
- Backups
- Encrypted, held in the same region, restore-tested quarterly with the results shared on request.
02
How it is protected
- In transit
- TLS 1.3 for all connections. SFTP endpoints accept key-based authentication only, no passwords.
- At rest
- AES-256 on all stored data, including source files, derived records and backups.
- Source files
- Hashed on arrival and stored immutably. A file cannot be altered after ingestion, including by us.
- Secrets
- Held in a managed secrets service with automatic rotation. No credential is ever written to a log.
- Segregation
- Production data is never copied to development or staging. Testing uses synthetic data, including ours.
03
Who can reach it
- Your access
- SAML SSO and SCIM on Scale and above. Roles scoped by entity and account: preparer, approver, viewer, administrator.
- Our access
- No standing access to customer data. Support access is time-bound, requires a named ticket, is approved by a second engineer, and is logged to a record you can read.
- Four-eyes
- Segregation of duties enforced in the product, configurable by value band, reason code and account. The approver can never be the preparer.
- Audit trail
- Append-only and hash-chained. Every read of customer data by Finlecy staff appears in your own access log.
04
How the model is used
- Boundary
- Language models classify unmatched records and write explanations. They never determine a match, compute an amount or authorise a posting.
- Training
- Your data is never used to train models, ours or anyone else's. There is no opt-out because there is nothing to opt out of.
- Retention at the provider
- Inference runs under zero-retention terms. Prompts and completions are not stored by the model provider.
- Minimisation
- Only the fields needed to classify a record are included in a prompt. Account numbers and personal data are excluded by construction, not by filtering.
- Verification
- Every model output passes a deterministic check — closed code list, balanced postings, permitted accounts — before a human ever sees it.
05
How we run
- Change management
- All changes peer-reviewed and deployed through an automated pipeline. Every deploy is attributable and revertible.
- Dependencies
- Automated vulnerability scanning on every build. Critical findings block the pipeline rather than raising a ticket.
- Penetration testing
- Annual third-party test. The report summary is available under NDA during a security review.
- Availability
- 99.9% commitment on Scale, 99.95% on Enterprise, measured monthly with service credits.
- Incident response
- Documented runbooks, a named on-call rota, and notification to affected customers without undue delay.
06
Retention and exit
- Default retention
- Seven years on Enterprise, two years on Scale, ninety days on Core. Configurable to your regulatory obligation.
- Legal hold
- Any period can be frozen against retention expiry and released by an authorised administrator.
- Deletion
- Verifiable deletion on request or contract end, including backups, within thirty days. A deletion certificate is issued.
- Export
- Your full history leaves in structured formats on request, at any time, at no charge. There is no exit fee and no export throttle.
Responsible disclosure
Found something? Tell us.
Report to security@finlecy.com. We acknowledge within one working day and give you a remediation timeline within five. We will not pursue legal action against anyone acting in good faith under this policy, and we will credit you publicly unless you prefer otherwise.
- Please do not access, modify or exfiltrate data that is not yours.
- Please do not run automated scanning that degrades service for customers.
- Please give us a reasonable window to remediate before publishing.
Running a security review?
Send the questionnaire. We complete them ourselves rather than routing them through a sales engineer, so the answers come from the people who built the thing.