> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usefini.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security questionnaire answers

> Fini's sourced answers to the 41 questions that come up most in vendor security questionnaires (SIG Lite and CAIQ style): certifications, encryption, residency, subprocessors, access control, incident response, BCDR, retention, and AI model training.

export const FilterTable = ({title, columns = [], rows = [], placeholder = "Search..."}) => {
  const FV = {
    lime: "#C3EE5E",
    ink: "#131415",
    line: "rgba(127,127,127,0.28)",
    soft: "rgba(127,127,127,0.07)",
    softer: "rgba(127,127,127,0.04)",
    muted: "rgba(127,127,127,0.95)",
    pass: "#C3EE5E",
    warn: "#FFB020",
    fail: "#FF4D4D",
    radius: 14
  };
  const fvCard = {
    border: `1px solid ${FV.line}`,
    borderRadius: FV.radius,
    padding: 18,
    margin: "20px 0",
    background: FV.softer
  };
  const fvChip = active => ({
    border: `1px solid ${active ? FV.lime : FV.line}`,
    background: active ? FV.lime : "transparent",
    color: active ? FV.ink : "inherit",
    borderRadius: 999,
    padding: "6px 12px",
    fontSize: 13,
    fontWeight: 600,
    cursor: "pointer",
    lineHeight: 1.2
  });
  const fvBtn = primary => ({
    border: `1px solid ${primary ? FV.lime : FV.line}`,
    background: primary ? FV.lime : "transparent",
    color: primary ? FV.ink : "inherit",
    borderRadius: 10,
    padding: "7px 14px",
    fontSize: 13,
    fontWeight: 600,
    cursor: "pointer"
  });
  const fvLabel = {
    fontSize: 11,
    fontWeight: 700,
    letterSpacing: "0.08em",
    textTransform: "uppercase",
    opacity: 0.6,
    marginBottom: 8
  };
  const [q, setQ] = useState("");
  const [cat, setCat] = useState("All");
  const cats = ["All", ...Array.from(new Set(rows.map(r => r.category).filter(Boolean)))];
  const ql = q.trim().toLowerCase();
  const shown = rows.filter(r => (cat === "All" || r.category === cat) && (!ql || r.cells.join(" ").toLowerCase().includes(ql)));
  return <div style={fvCard}>
      {title && <div style={fvLabel}>{title}</div>}
      <input value={q} onChange={e => setQ(e.target.value)} placeholder={placeholder} style={{
    width: "100%",
    boxSizing: "border-box",
    border: `1px solid ${FV.line}`,
    borderRadius: 10,
    padding: "8px 12px",
    background: "transparent",
    color: "inherit",
    fontSize: 14,
    marginBottom: 10
  }} />
      {cats.length > 2 && <div style={{
    display: "flex",
    gap: 6,
    flexWrap: "wrap",
    marginBottom: 10
  }}>
          {cats.map(c => <button key={c} style={fvChip(c === cat)} onClick={() => setCat(c)}>{c}</button>)}
        </div>}
      <div style={{
    overflowX: "auto"
  }}>
        <table style={{
    width: "100%",
    borderCollapse: "collapse",
    fontSize: 13.5
  }}>
          <thead><tr>{columns.map((c, i) => <th key={i} style={{
    textAlign: "left",
    padding: "8px 10px",
    borderBottom: `1px solid ${FV.line}`,
    whiteSpace: "nowrap"
  }}>{c}</th>)}</tr></thead>
          <tbody>
            {shown.map((r, i) => <tr key={i}>{r.cells.map((c, j) => <td key={j} style={{
    padding: "8px 10px",
    borderBottom: `1px solid ${FV.line}`,
    verticalAlign: "top",
    fontWeight: j === 0 ? 600 : 400
  }}>{c}</td>)}</tr>)}
            {shown.length === 0 && <tr><td colSpan={columns.length} style={{
    padding: 12,
    opacity: 0.6
  }}>No matches.</td></tr>}
          </tbody>
        </table>
      </div>
      <div style={{
    fontSize: 12,
    opacity: 0.6,
    marginTop: 8
  }}>{shown.length} of {rows.length} shown</div>
    </div>;
};

Fini (usefini.com) is SOC 2 Type II compliant, ISO/IEC 27001:2022 certified, PCI DSS Level 1 certified, HIPAA-compliant and BAA-eligible, supports GDPR and CCPA, encrypts customer data with AES-256 at rest and TLS 1.2+ in transit, and does not use customer data to train foundation models. This page answers the questions security and procurement teams ask most often, with a source for every answer, so you can fill most of a SIG Lite or CAIQ style questionnaire without waiting on a call.

The [Fini Trust Center](https://security.usefini.com/) is the primary source for security documentation. Reports, policies, and the completed vendor security questionnaire listed there are shared on request through the Trust Center's **Get access** flow. Where an answer below says "Available via the Trust Center on request", the Trust Center lists that document.

<Info>
  **How to use this page.** Copy answers directly into your questionnaire, and attach the documents you request from the Trust Center as evidence. Contractual commitments (breach notice, subprocessor notice, transfer mechanisms) are set by the [Data Processing Addendum](https://www.usefini.com/security/data-processing-addendum) and your MSA; if this page and a signed agreement ever differ, the agreement wins.
</Info>

Search or filter every answer here. The sourced tables below carry the same answers with links to each source document.

<FilterTable
  title="Search all 41 answers"
  columns={["#", "Question", "Fini's answer", "Source"]}
  rows={[
{ cells: ["1", "Are you SOC 2 Type II compliant?", "Yes. Fini is SOC 2 Type II compliant. The SOC 2 Type II report is available via the Trust Center on request.", "Trust Center, SOC 2 and ISO 27001"], category: "Certifications" },
{ cells: ["2", "Are you ISO/IEC 27001 certified?", "Yes. Fini is ISO/IEC 27001:2022 certified. The ISO/IEC 27001 documentation is available via the Trust Center on request.", "Trust Center"], category: "Certifications" },
{ cells: ["3", "Are you PCI DSS certified?", "Yes. Fini is PCI DSS Level 1 certified, the highest level of the Payment Card Industry Data Security Standard. Card numbers are masked automatically in stored conversation data, and card actions run in your payment provider's systems through Actions. To request the attestation (AOC), contact your Fini account team.", "PCI DSS"], category: "Certifications" },
{ cells: ["4", "Do you comply with GDPR?", "Yes. Fini acts as processor for Customer Data under the DPA (v1.0.5), with EU Standard Contractual Clauses (Modules Two and Three) and Swiss and UK addenda.", "DPA"], category: "Certifications" },
{ cells: ["5", "Do you comply with CCPA and other US state privacy laws?", "Yes. The DPA covers Fini's processor obligations under CCPA and other US state privacy laws.", "DPA"], category: "Certifications" },
{ cells: ["6", "Can you handle PHI, and will you sign a BAA?", "Yes. Fini is HIPAA-compliant and BAA-eligible for enterprise customers. Fini's BAA template or yours both work, typical turnaround is about one week, and you request it through your Fini account team.", "HIPAA and BAAs"], category: "Certifications" },
{ cells: ["7", "Do you mask card numbers and sensitive data in conversations?", "Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. Keep card numbers, CVVs and unnecessary health details out of conversations: don't ask customers for them, and route card actions through your payment provider via Actions. Guardrails add an extra layer on what the agent says.", "Data handling"], category: "Data and residency" },
{ cells: ["8", "Do you perform independent penetration testing? Can we see the report?", "Yes. Fini performs annual third-party penetration testing. The pentest report is available via the Trust Center on request.", "Trust Center"], category: "Certifications" },
{ cells: ["9", "Do you have a completed standard security questionnaire?", "Yes. A completed Vendor Security Alliance questionnaire (VSA Full) is available via the Trust Center on request.", "Trust Center"], category: "Certifications" },
{ cells: ["10", "Do you conduct regular risk assessments?", "Yes. Fini conducts an annual risk assessment. The Risk Assessment/Management Policy is available via the Trust Center on request.", "Trust Center"], category: "Certifications" },
{ cells: ["11", "Is customer data encrypted at rest?", "Yes. All customer data is encrypted at rest with AES-256. The Encryption Policy is available via the Trust Center on request.", "Trust Center"], category: "Data and residency" },
{ cells: ["12", "Is customer data encrypted in transit?", "Yes, with TLS 1.2 or higher.", "Trust Center"], category: "Data and residency" },
{ cells: ["13", "Where is customer data stored? Can we choose the region?", "In the region you designate: United States or European Union. With EU data residency, data is stored and processed in the EU. Fini's infrastructure runs on Google Cloud in multiple US and EU regions.", "Data handling, Trust Center"], category: "Data and residency" },
{ cells: ["14", "Who hosts the service?", "Google Cloud. Physical security of the infrastructure is managed by Google Cloud. An Azure-hosted deployment in your own Azure tenant is available through Microsoft Marketplace, with Entra ID, Private Link, VNet, and customer-managed keys. Calls Fini makes to your APIs (Actions) come from four static IPs in Google Cloud's europe-west4 region (Netherlands), for every workspace, so you can allowlist them.", "Trust Center, Fini on Azure, Static IP Addresses"], category: "Data and residency" },
{ cells: ["15", "Which subprocessors do you use, and how are changes communicated?", "Google Cloud (including Gemini; hosting, AI), Microsoft Azure (Azure Marketplace deployments, including Azure AI Foundry and Azure OpenAI), Supabase (managed database), OpenAI and Anthropic (LLM inference, enterprise agreements), PostHog (product analytics, usage metrics only), Sentry (error monitoring and logging), Stripe (billing), Linear (issue tracking), Google (email) and Langfuse (tracing). The DPA gives 30 days' notice of subprocessor changes.", "DPA, Trust Center"], category: "Data and residency" },
{ cells: ["16", "Will you sign a DPA?", "Yes. Fini's DPA (v1.0.5) is published and available to customers.", "DPA"], category: "Data and residency" },
{ cells: ["17", "How long do you retain customer data? Can we request deletion?", "You set your own retention period, and deletion removes all data. On termination, data is deleted within 30 days under the Terms of Service.", "Trust Center, Terms of Service"], category: "Data and residency" },
{ cells: ["18", "Is customer data used in development or test environments?", "No. Customer data is not used in non-production environments.", "Trust Center"], category: "Data and residency" },
{ cells: ["19", "Do you back up customer data?", "Yes, on a regular basis, to recover from incidents that cause data loss. The Backup Policy is available via the Trust Center on request.", "Trust Center"], category: "Data and residency" },
{ cells: ["20", "Do you classify data?", "Yes. The Data Classification Policy is available via the Trust Center on request.", "Trust Center"], category: "Data and residency" },
{ cells: ["21", "Is our data used to train AI models?", "No. Fini does not use customer data to train foundation models. Any per-customer learning happens only inside that customer's environment and only with their written authorization. Fini's LLM subprocessors are contractually barred from training on it, and the DPA sets this commitment.", "DPA, Data handling"], category: "AI and models" },
{ cells: ["22", "Which AI model providers process our data?", "OpenAI, Anthropic and Google (Gemini, through Google Cloud). With EU data residency, data is stored and processed in the EU. For an Azure-hosted deployment bought through Microsoft Marketplace, models run on Azure AI Foundry and Azure OpenAI Service in your Azure tenant.", "Trust Center, Fini on Azure"], category: "AI and models" },
{ cells: ["23", "How is personal data in conversations protected?", "Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. As an extra layer, Guardrails check every generated reply before delivery. The Confidential attributes check blocks the values of user attributes you select from appearing in replies (it matches values; it is not blanket PII detection). If a reply can't be rewritten safely, Fini replaces it with a handoff and escalates. Safety-triggered escalations show in Analytics under Guardrail or Safety Trigger.", "Guardrails, Analytics"], category: "AI and models" },
{ cells: ["24", "How do you control what the AI says and does?", "Regulated workflows run as deterministic Intent Rules: the same conversation context produces the same tree walk and the same API call every time. Guardrails add banned-term, URL allowlist, AI disclosure, and custom checks, and Reply Rules decide when the agent replies, leaves an internal note, or stays silent.", "Intent Rules, Guardrails"], category: "AI and models" },
{ cells: ["25", "Can you show why the AI made a given decision?", "Yes. Every conversation in Inbox has an AI Steps trace showing the attributes fetched, the rule steps that ran with pass or fail status, guardrail verdicts, and the reasoning behind its tags.", "AI Steps trace"], category: "AI and models" },
{ cells: ["26", "Do you support SSO?", "Yes. Fini supports single sign-on with Okta, Google, Slack and Microsoft Entra ID. The setup guide in the docs covers Okta.", "Okta SSO"], category: "Access" },
{ cells: ["27", "Do you support multi-factor authentication?", "The Trust Center lists multi-factor authentication as implemented.", "Trust Center"], category: "Access" },
{ cells: ["28", "Do you support role-based access control?", "Yes. The Trust Center lists role-based access control. The Access Control Policy is available via the Trust Center on request.", "Trust Center"], category: "Access" },
{ cells: ["29", "How is employee access to customer data controlled and monitored?", "Access is provisioned under Fini's Access Control Policy, and access to the portal is monitored with Google Cloud Security Command Center.", "Trust Center"], category: "Access" },
{ cells: ["30", "How are API keys and credentials protected?", "API keys are scoped (for example, read for non-mutating operations) and stored in an encrypted database. User credentials are salted, hashed, and stored by Supabase, and infrastructure secrets are kept in a secure key vault.", "API keys, Trust Center"], category: "Access" },
{ cells: ["31", "Do you keep audit logs?", "Yes. The Trust Center lists audit logging, and important infrastructure logs are centrally stored and monitored (SIEM). Customers can export audit logs. Per-conversation decisions are recorded in the AI Steps trace.", "Trust Center"], category: "Monitoring" },
{ cells: ["32", "How do you detect intrusions and threats?", "Firewalls control traffic, network activity is centrally logged with detection logic for anomalous behavior (IDS/IPS), and Fini's team monitors for known attacker techniques and hunts for unknown threats on a regular cadence.", "Trust Center"], category: "Monitoring" },
{ cells: ["33", "How do you manage vulnerabilities and patching?", "Fini runs a formal vulnerability management process and applies patches on a documented SLA. Code and third-party dependencies are scanned, and the secure development policy requires peer review, automated testing, and static code analysis before production. The Vulnerability Management Policy is available via the Trust Center on request.", "Trust Center"], category: "Monitoring" },
{ cells: ["34", "Do you have a vulnerability disclosure process?", "Yes. Report suspected vulnerabilities through Report issue on the Trust Center.", "Trust Center"], category: "Monitoring" },
{ cells: ["35", "Do you have an incident response plan?", "Yes. Fini has a documented Incident Response Plan that is reviewed, tested, and approved at least annually. The Incident Response Policy is available via the Trust Center on request.", "Trust Center"], category: "Incident and BCDR" },
{ cells: ["36", "How quickly will you notify us of a breach?", "Within 72 hours of a personal data breach involving Customer Data, under the DPA.", "DPA"], category: "Incident and BCDR" },
{ cells: ["37", "Do you have a BC/DR plan? What is your RTO?", "Yes. Fini has a formal Business Continuity and Disaster Recovery plan, exercised, reviewed, and approved annually. The Trust Center risk profile lists a Recovery Time Objective of 24-48 hours. The BC/DR Policy is available via the Trust Center on request.", "Trust Center"], category: "Incident and BCDR" },
{ cells: ["38", "What uptime do you commit to?", "A 99.9% monthly uptime target under the Terms of Service. Contractual SLAs are defined in the customer's MSA.", "Terms of Service"], category: "Incident and BCDR" },
{ cells: ["39", "Do employees undergo background checks and security training?", "Yes. New employees pass a background check and sign an NDA, and all personnel complete security and privacy awareness training annually (passwords, mobile devices, social engineering, physical security, phishing, and GDPR).", "Trust Center"], category: "People" },
{ cells: ["40", "How are employee devices secured?", "Employee endpoints use full-disk encryption, central management through MDM, endpoint detection and response, and DNS filtering.", "Trust Center"], category: "People" },
{ cells: ["41", "Do you carry cyber insurance?", "Yes. Cyber insurance is in place. The Cyber Insurance document is available via the Trust Center on request.", "Trust Center"], category: "People" }
]}
  placeholder="Search questions and answers, for example encryption or SSO"
/>

## Certifications and assessments

| # | Question | Fini's answer | Source |
| - | - | - | - |
| 1 | Are you SOC 2 Type II compliant? | Yes. Fini is SOC 2 Type II compliant. The SOC 2 Type II report is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/), [SOC 2 and ISO 27001](/en/security/soc2-iso27001) |
| 2 | Are you ISO/IEC 27001 certified? | Yes. Fini is ISO/IEC 27001:2022 certified. The ISO/IEC 27001 documentation is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |
| 3 | Are you PCI DSS certified? | Yes. Fini is PCI DSS Level 1 certified, the highest level of the Payment Card Industry Data Security Standard. Card numbers are masked automatically in stored conversation data, and card actions run in your payment provider's systems through Actions. To request the attestation (AOC), contact your Fini account team. | [PCI DSS](/en/security/pci-dss) |
| 4 | Do you comply with GDPR? | Yes. Fini acts as processor for Customer Data under the DPA (v1.0.5), with EU Standard Contractual Clauses (Modules Two and Three) and Swiss and UK addenda. | [DPA](https://www.usefini.com/security/data-processing-addendum) |
| 5 | Do you comply with CCPA and other US state privacy laws? | Yes. The DPA covers Fini's processor obligations under CCPA and other US state privacy laws. | [DPA](https://www.usefini.com/security/data-processing-addendum) |
| 6 | Can you handle PHI, and will you sign a BAA? | Yes. Fini is HIPAA-compliant and BAA-eligible for enterprise customers. Fini's BAA template or yours both work, typical turnaround is about one week, and you request it through your Fini account team. | [HIPAA and BAAs](/en/security/hipaa) |
| 7 | Do you mask card numbers and sensitive data in conversations? | Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. Keep card numbers, CVVs and unnecessary health details out of conversations: don't ask customers for them, and route card actions through your payment provider via [Actions](/en/api-reference/actions). [Guardrails](/en/configuration/guardrails) add an extra layer on what the agent says. | [Data handling](/en/security/data-handling#masking-sensitive-data) |
| 8 | Do you perform independent penetration testing? Can we see the report? | Yes. Fini performs annual third-party penetration testing. The pentest report is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |
| 9 | Do you have a completed standard security questionnaire? | Yes. A completed Vendor Security Alliance questionnaire (VSA Full) is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |
| 10 | Do you conduct regular risk assessments? | Yes. Fini conducts an annual risk assessment. The Risk Assessment/Management Policy is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |

## Data protection and residency

| # | Question | Fini's answer | Source |
| - | - | - | - |
| 11 | Is customer data encrypted at rest? | Yes. All customer data is encrypted at rest with AES-256. The Encryption Policy is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |
| 12 | Is customer data encrypted in transit? | Yes, with TLS 1.2 or higher. | [Trust Center](https://security.usefini.com/) |
| 13 | Where is customer data stored? Can we choose the region? | In the region you designate: United States or European Union. With EU data residency, data is stored and processed in the EU. Fini's infrastructure runs on Google Cloud in multiple US and EU regions. | [Data handling](/en/security/data-handling), [Trust Center](https://security.usefini.com/) |
| 14 | Who hosts the service? | Google Cloud. Physical security of the infrastructure is managed by Google Cloud. An Azure-hosted deployment in your own Azure tenant is available through Microsoft Marketplace, with Entra ID, Private Link, VNet, and customer-managed keys. Calls Fini makes to your APIs (Actions) come from four static IPs in Google Cloud's europe-west4 region (Netherlands), for every workspace, so you can allowlist them. | [Trust Center](https://security.usefini.com/), [Fini on Azure](https://www.usefini.com/better-together), [Static IP Addresses](/en/api-reference/static-ip) |
| 15 | Which subprocessors do you use, and how are changes communicated? | Google Cloud (including Gemini; hosting, AI), Microsoft Azure (Azure Marketplace deployments, including Azure AI Foundry and Azure OpenAI), Supabase (managed database), OpenAI and Anthropic (LLM inference, enterprise agreements), PostHog (product analytics, usage metrics only), Sentry (error monitoring and logging), Stripe (billing), Linear (issue tracking), Google (email) and Langfuse (tracing). The DPA gives 30 days' notice of subprocessor changes. | [Trust Center](https://security.usefini.com/), [DPA](https://www.usefini.com/security/data-processing-addendum) |
| 16 | Will you sign a DPA? | Yes. Fini's DPA (v1.0.5) is published and available to customers. | [DPA](https://www.usefini.com/security/data-processing-addendum) |
| 17 | How long do you retain customer data? Can we request deletion? | You set your own retention period, and deletion removes all data. On termination, data is deleted within 30 days under the Terms of Service. | [Trust Center](https://security.usefini.com/), [Terms of Service](https://www.usefini.com/security/terms-of-service) |
| 18 | Is customer data used in development or test environments? | No. Customer data is not used in non-production environments. | [Trust Center](https://security.usefini.com/) |
| 19 | Do you back up customer data? | Yes, on a regular basis, to recover from incidents that cause data loss. The Backup Policy is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |
| 20 | Do you classify data? | Yes. The Data Classification Policy is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |

## AI and model use

| # | Question | Fini's answer | Source |
| - | - | - | - |
| 21 | Is our data used to train AI models? | No. Fini does not use customer data to train foundation models. Any per-customer learning happens only inside that customer's environment and only with their written authorization. Fini's LLM subprocessors are contractually barred from training on it, and the DPA sets this commitment. | [DPA](https://www.usefini.com/security/data-processing-addendum), [Data handling](/en/security/data-handling) |
| 22 | Which AI model providers process our data? | OpenAI, Anthropic and Google (Gemini, through Google Cloud). With EU data residency, data is stored and processed in the EU. For an Azure-hosted deployment bought through Microsoft Marketplace, models run on Azure AI Foundry and Azure OpenAI Service in your Azure tenant. | [Trust Center](https://security.usefini.com/), [Fini on Azure](https://www.usefini.com/better-together) |
| 23 | How is personal data in conversations protected? | Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. As an extra layer, [Guardrails](/en/configuration/guardrails) check every generated reply before delivery. The **Confidential attributes** check blocks the values of user attributes you select from appearing in replies (it matches values; it is not blanket PII detection). If a reply can't be rewritten safely, Fini replaces it with a handoff and escalates. Safety-triggered escalations show in Analytics under **Guardrail or Safety Trigger**. | [Guardrails](/en/configuration/guardrails), [Analytics](/en/analytics#escalation-reasons) |
| 24 | How do you control what the AI says and does? | Regulated workflows run as deterministic [Intent Rules](/en/automations/rulebook): the same conversation context produces the same tree walk and the same API call every time. Guardrails add banned-term, URL allowlist, AI disclosure, and custom checks, and [Reply Rules](/en/automations/reply-behavior) decide when the agent replies, leaves an internal note, or stays silent. | [Intent Rules](/en/automations/rulebook), [Guardrails](/en/configuration/guardrails) |
| 25 | Can you show why the AI made a given decision? | Yes. Every conversation in [Inbox](/en/testing/inbox) has an **AI Steps** trace showing the attributes fetched, the rule steps that ran with pass or fail status, guardrail verdicts, and the reasoning behind its tags. | [AI Steps trace](/en/automations/rulebook#observability-the-ai-steps-trace) |

## Access control and authentication

| # | Question | Fini's answer | Source |
| - | - | - | - |
| 26 | Do you support SSO? | Yes. Fini supports single sign-on with Okta, Google, Slack and Microsoft Entra ID. The setup guide in the docs covers Okta. | [Okta SSO](/en/sso-login) |
| 27 | Do you support multi-factor authentication? | The Trust Center lists multi-factor authentication as implemented. | [Trust Center](https://security.usefini.com/) |
| 28 | Do you support role-based access control? | Yes. The Trust Center lists role-based access control. The Access Control Policy is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |
| 29 | How is employee access to customer data controlled and monitored? | Access is provisioned under Fini's Access Control Policy, and access to the portal is monitored with Google Cloud Security Command Center. | [Trust Center](https://security.usefini.com/) |
| 30 | How are API keys and credentials protected? | API keys are scoped (for example, `read` for non-mutating operations) and stored in an encrypted database. User credentials are salted, hashed, and stored by Supabase, and infrastructure secrets are kept in a secure key vault. | [API keys](/en/deploy/api-keys), [Trust Center](https://security.usefini.com/) |

## Logging, monitoring, and vulnerability management

| # | Question | Fini's answer | Source |
| - | - | - | - |
| 31 | Do you keep audit logs? | Yes. The Trust Center lists audit logging, and important infrastructure logs are centrally stored and monitored (SIEM). Customers can export audit logs. Per-conversation decisions are recorded in the AI Steps trace. | [Trust Center](https://security.usefini.com/) |
| 32 | How do you detect intrusions and threats? | Firewalls control traffic, network activity is centrally logged with detection logic for anomalous behavior (IDS/IPS), and Fini's team monitors for known attacker techniques and hunts for unknown threats on a regular cadence. | [Trust Center](https://security.usefini.com/) |
| 33 | How do you manage vulnerabilities and patching? | Fini runs a formal vulnerability management process and applies patches on a documented SLA. Code and third-party dependencies are scanned, and the secure development policy requires peer review, automated testing, and static code analysis before production. The Vulnerability Management Policy is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |
| 34 | Do you have a vulnerability disclosure process? | Yes. Report suspected vulnerabilities through **Report issue** on the Trust Center. | [Trust Center](https://security.usefini.com/) |

## Incident response and business continuity

| # | Question | Fini's answer | Source |
| - | - | - | - |
| 35 | Do you have an incident response plan? | Yes. Fini has a documented Incident Response Plan that is reviewed, tested, and approved at least annually. The Incident Response Policy is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |
| 36 | How quickly will you notify us of a breach? | Within 72 hours of a personal data breach involving Customer Data, under the DPA. | [DPA](https://www.usefini.com/security/data-processing-addendum) |
| 37 | Do you have a BC/DR plan? What is your RTO? | Yes. Fini has a formal Business Continuity and Disaster Recovery plan, exercised, reviewed, and approved annually. The Trust Center risk profile lists a Recovery Time Objective of 24-48 hours. The BC/DR Policy is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |
| 38 | What uptime do you commit to? | A 99.9% monthly uptime target under the Terms of Service. Contractual SLAs are defined in the customer's MSA. | [Terms of Service](https://www.usefini.com/security/terms-of-service) |

## People and corporate security

| # | Question | Fini's answer | Source |
| - | - | - | - |
| 39 | Do employees undergo background checks and security training? | Yes. New employees pass a background check and sign an NDA, and all personnel complete security and privacy awareness training annually (passwords, mobile devices, social engineering, physical security, phishing, and GDPR). | [Trust Center](https://security.usefini.com/) |
| 40 | How are employee devices secured? | Employee endpoints use full-disk encryption, central management through MDM, endpoint detection and response, and DNS filtering. | [Trust Center](https://security.usefini.com/) |
| 41 | Do you carry cyber insurance? | Yes. Cyber insurance is in place. The Cyber Insurance document is available via the Trust Center on request. | [Trust Center](https://security.usefini.com/) |

Customers can also request Fini's compliance reports (SOC 2, ISO 27001:2022, GDPR) under the Trust Center's customer audit rights, and the PCI DSS Level 1 attestation (AOC) from their Fini account team. For privacy and legal questions, contact [legal@usefini.com](mailto:legal@usefini.com).

## Related

<CardGroup cols={2}>
  <Card title="Security overview" icon="shield-halved" href="/en/security/overview">
    How Fini secures customer data, and where each document lives.
  </Card>

  <Card title="Data handling, residency and model training" icon="database" href="/en/security/data-handling">
    Residency, retention, subprocessors, and model training in depth.
  </Card>

  <Card title="Questions to ask an AI support vendor" icon="list-check" href="/en/evaluate/questions-to-ask">
    Evaluation questions beyond security, with Fini's answers.
  </Card>

  <Card title="RFP fact sheet" icon="file-lines" href="/en/evaluate/rfp-fact-sheet">
    Copy-ready company and product facts for RFPs.
  </Card>
</CardGroup>


## Related topics

- [Questions to ask an AI support vendor, with Fini's answers](/en/evaluate/questions-to-ask.md)
- [RFP fact sheet](/en/evaluate/rfp-fact-sheet.md)
- [Billing FAQ](/en/billing/billing-faq.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.