Fini’s certifications, encryption, data residency, hosting and legal terms in one table, plus the product controls your team configures and where to get audit reports.
Fini (usefini.com) is SOC 2 Type II compliant, ISO/IEC 27001:2022 certified, PCI DSS Level 1 certified, HIPAA-compliant and BAA-eligible, and supports GDPR and CCPA obligations. Customer data is encrypted with AES-256 at rest and TLS 1.2+ in transit, stays in your choice of US or EU region, and Fini does not use customer data to train foundation models.This page is written for security, privacy and procurement reviewers. It summarizes Fini’s posture, tells you where to get the evidence (audit reports, pen-test report, DPA), and lists the controls your own team configures inside the product. Fini’s policies and reports live in the Trust Center; this page links to them rather than restating them.
Fini does not use customer data to train foundation models. Any per-customer learning happens only inside that customer’s environment and only with their written authorization. LLM subprocessors are contractually barred from training on it.
DPA
Sensitive data masking
Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps
Google Cloud (including Gemini), Microsoft Azure, Supabase, OpenAI, Anthropic, PostHog, Sentry, Stripe, Linear, Google (email) and Langfuse; 30 days’ notice of changes. Purposes are listed in Data handling.
DPA, Trust Center
Single sign-on
Okta, Google, Slack and Microsoft Entra ID (the setup guide covers Okta)
In place; the Cyber Insurance document is available on request
Trust Center
The Trust Center risk profile also classifies Fini at Data Access Level: Internal and Impact Level: Moderate. Use those values if your vendor-risk tool asks for the vendor’s self-assessed tier.
Fini’s Trust Center at security.usefini.com is the single place for security documentation. Public sections cover product security, data security, app security, infrastructure, endpoint, network and corporate security, legal, and policies. Sensitive documents are gated and released on request.
1
Open the Trust Center
Go to security.usefini.com and click Get access (or Start your security review).
2
Request the documents you need
The featured documents are the Pentest Report, ISO/IEC 27001, SOC 2, Cyber Insurance and Data Processing Agreement. The Reports section also lists a Network Diagram, and Self-Assessments include a VSA Full questionnaire.
3
Ask follow-up questions
Use Ask for information in the Trust Center for anything not covered by the documents. Report a suspected vulnerability with Report issue.
Start with the VSA Full self-assessment and the SOC 2 report before sending your own questionnaire. Many questions in a standard vendor security questionnaire are answered there already, so your follow-up list is shorter.
Certifications cover how Fini runs its platform. The controls below are the ones you own inside your workspace. A security review is stronger when it covers both.
Control
What it does
Where
Single sign-on
Your team signs into the Fini dashboard with Okta, Google, Slack or Microsoft Entra ID. With Okta, only users assigned to the SAML app can sign in, so offboarding in your IdP removes access.
Workspace keys carry read, write or both. Keys are shown once, can be revoked individually, and revocation is immediate. Keep write off for export-only integrations.
When an Action calls your systems, the request originates from four fixed IP addresses in Google Cloud’s europe-west4 region (Netherlands), for every workspace. You can allowlist them on port 443.
An extra layer on top of automatic masking. Checks run on every generated reply before delivery: Confidential attributes (values of selected user attributes must not appear in replies), Banned terms, URL allowlist, AI disclosure, Internal reasoning leak, and up to 10 Custom rule checks.
Decide per conversation whether the agent sends a Direct Reply, leaves an Internal Comment for your team only, or sends No Reply. The stricter behavior always wins.
Actions run only when a Tool node in a published Intent Rule or Business Rule invokes them, so the agent cannot call an API outside a rule you built and tested.
Every Fini reply has an AI Steps trace: knowledge retrieved, rules and nodes executed, user attributes loaded, tags applied, guardrail verdicts and the model’s reasoning.
Guardrails are not a fail-closed security boundary. If a check errors or times out, the original reply can be sent unchanged. Treat Guardrails as one layer alongside Reply Rules, Rulebook design and Test Suite coverage, and review per-check verdicts in AI Steps. See Guardrails.
No. Fini does not use customer data to train foundation models. Any per-customer learning happens only inside that customer’s environment and only with their written authorization. Fini’s LLM subprocessors are contractually barred from training on it. This commitment is in the DPA. See Data handling.
Where is our data stored?
In the region you designate: the United States or the European Union. With EU data residency, data is stored and processed in the EU. Fini runs on Google Cloud. If you buy through Microsoft Marketplace, Fini can run on Azure in your own tenant, with Private Link, VNet support, customer-managed encryption keys, Entra ID and Conditional Access. See Data handling.
Which identity providers work for SSO?
Fini supports single sign-on with Okta, Google, Slack and Microsoft Entra ID. The setup guide covers Okta step by step: Okta SSO.
Who are Fini's subprocessors?
Google Cloud (including Gemini) for hosting and AI, Microsoft Azure for Azure Marketplace deployments (including Azure AI Foundry and Azure OpenAI), Supabase as the managed database, OpenAI and Anthropic for LLM inference under enterprise agreements, PostHog for product analytics (usage metrics only), Sentry for error monitoring and logging, Stripe for billing, Linear for issue tracking, Google for email, and Langfuse for tracing. Fini gives 30 days’ notice of subprocessor changes under the DPA. See Data handling.
Can the AI agent take actions we haven't approved?
No. An Action runs only when a Tool node in a published rule invokes it, and Intent Rule execution is deterministic: the same conversation context produces the same tree walk. You decide which Actions exist, which rules call them, and which agents those rules are assigned to. Every Action call is recorded in the AI Steps trace. See Rulebook.
How do we audit what the agent said and why?
Open the conversation in Inbox and click the light bulb icon on any Fini reply. The AI Steps sidebar shows Planning, Executed User Attributes, Executed Rule, Generate Answer, tag selection with reasoning, and Guardrails verdicts, in execution order.
Does Fini store card numbers or health data from conversations?
Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. Design workflows so card numbers, CVVs and health details never need to enter the conversation: don’t ask customers for them, and route card actions through your payment provider via Actions. Configure Guardrails as an extra layer. See Data handling.
Can we export audit logs?
Yes. Customers can export audit logs. For reply-level reasoning, use the AI Steps trace in Inbox.