Skip to content
Finlecy

Security

What we do with your data, stated plainly

You are considering sending us statements and ledgers for a regulated business. That deserves specifics rather than a badge wall, including the parts where the honest answer is “not yet”.

Our certification position, without the ambiguity

Finlecy is not currently certified to ISO/IEC 27001 or attested under SOC 2. We are a small company and we would rather say that here than have you discover it in week three of a procurement process. What we do have is the set of controls below, an annual third-party penetration test, and a completed CAIQ-Lite questionnaire we will send on request.

If a certification is a hard requirement for your risk function, tell us early. We will tell you honestly whether our timeline can meet yours rather than running a sales process around it.

01

Where your data lives

Processing region
European Union, single region. No processing outside the EU, including for support and diagnostics.
Sub-processors
A published list, with thirty days' notice before any addition. Every sub-processor is EU-resident.
Isolation
Logical isolation per customer on shared plans. Single-tenant deployment available on Enterprise, or deployment inside your own VPC.
Backups
Encrypted, held in the same region, restore-tested quarterly with the results shared on request.

02

How it is protected

In transit
TLS 1.3 for all connections. SFTP endpoints accept key-based authentication only, no passwords.
At rest
AES-256 on all stored data, including source files, derived records and backups.
Source files
Hashed on arrival and stored immutably. A file cannot be altered after ingestion, including by us.
Secrets
Held in a managed secrets service with automatic rotation. No credential is ever written to a log.
Segregation
Production data is never copied to development or staging. Testing uses synthetic data, including ours.

03

Who can reach it

Your access
SAML SSO and SCIM on Scale and above. Roles scoped by entity and account: preparer, approver, viewer, administrator.
Our access
No standing access to customer data. Support access is time-bound, requires a named ticket, is approved by a second engineer, and is logged to a record you can read.
Four-eyes
Segregation of duties enforced in the product, configurable by value band, reason code and account. The approver can never be the preparer.
Audit trail
Append-only and hash-chained. Every read of customer data by Finlecy staff appears in your own access log.

04

How the model is used

Boundary
Language models classify unmatched records and write explanations. They never determine a match, compute an amount or authorise a posting.
Training
Your data is never used to train models, ours or anyone else's. There is no opt-out because there is nothing to opt out of.
Retention at the provider
Inference runs under zero-retention terms. Prompts and completions are not stored by the model provider.
Minimisation
Only the fields needed to classify a record are included in a prompt. Account numbers and personal data are excluded by construction, not by filtering.
Verification
Every model output passes a deterministic check — closed code list, balanced postings, permitted accounts — before a human ever sees it.

05

How we run

Change management
All changes peer-reviewed and deployed through an automated pipeline. Every deploy is attributable and revertible.
Dependencies
Automated vulnerability scanning on every build. Critical findings block the pipeline rather than raising a ticket.
Penetration testing
Annual third-party test. The report summary is available under NDA during a security review.
Availability
99.9% commitment on Scale, 99.95% on Enterprise, measured monthly with service credits.
Incident response
Documented runbooks, a named on-call rota, and notification to affected customers without undue delay.

06

Retention and exit

Default retention
Seven years on Enterprise, two years on Scale, ninety days on Core. Configurable to your regulatory obligation.
Legal hold
Any period can be frozen against retention expiry and released by an authorised administrator.
Deletion
Verifiable deletion on request or contract end, including backups, within thirty days. A deletion certificate is issued.
Export
Your full history leaves in structured formats on request, at any time, at no charge. There is no exit fee and no export throttle.

Responsible disclosure

Found something? Tell us.

Report to security@finlecy.com. We acknowledge within one working day and give you a remediation timeline within five. We will not pursue legal action against anyone acting in good faith under this policy, and we will credit you publicly unless you prefer otherwise.

  • Please do not access, modify or exfiltrate data that is not yours.
  • Please do not run automated scanning that degrades service for customers.
  • Please give us a reasonable window to remediate before publishing.

Running a security review?

Send the questionnaire. We complete them ourselves rather than routing them through a sales engineer, so the answers come from the people who built the thing.

Finlecy, C/ Hijuela de Lojo 75, 20491 Belauntza, Guipúzcoa, Spain