Skip to main content
Fini (usefini.com) is SOC 2 Type II compliant, ISO/IEC 27001:2022 certified, PCI DSS Level 1 certified, HIPAA-compliant and BAA-eligible, and supports GDPR and CCPA obligations. Customer data is encrypted with AES-256 at rest and TLS 1.2+ in transit, stays in your choice of US or EU region, and Fini does not use customer data to train foundation models. This page is written for security, privacy and procurement reviewers. It summarizes Fini’s posture, tells you where to get the evidence (audit reports, pen-test report, DPA), and lists the controls your own team configures inside the product. Fini’s policies and reports live in the Trust Center; this page links to them rather than restating them.

Posture at a glance

The Trust Center risk profile also classifies Fini at Data Access Level: Internal and Impact Level: Moderate. Use those values if your vendor-risk tool asks for the vendor’s self-assessed tier.

Getting the evidence

Fini’s Trust Center at security.usefini.com is the single place for security documentation. Public sections cover product security, data security, app security, infrastructure, endpoint, network and corporate security, legal, and policies. Sensitive documents are gated and released on request.
1

Open the Trust Center

Go to security.usefini.com and click Get access (or Start your security review).
2

Request the documents you need

The featured documents are the Pentest Report, ISO/IEC 27001, SOC 2, Cyber Insurance and Data Processing Agreement. The Reports section also lists a Network Diagram, and Self-Assessments include a VSA Full questionnaire.
3

Ask follow-up questions

Use Ask for information in the Trust Center for anything not covered by the documents. Report a suspected vulnerability with Report issue.
Start with the VSA Full self-assessment and the SOC 2 report before sending your own questionnaire. Many questions in a standard vendor security questionnaire are answered there already, so your follow-up list is shorter.
Legal terms are published on usefini.com: For legal and privacy questions, contact [email protected].

Controls your team configures

Certifications cover how Fini runs its platform. The controls below are the ones you own inside your workspace. A security review is stronger when it covers both.
Guardrails are not a fail-closed security boundary. If a check errors or times out, the original reply can be sent unchanged. Treat Guardrails as one layer alongside Reply Rules, Rulebook design and Test Suite coverage, and review per-check verdicts in AI Steps. See Guardrails.

Reviewer FAQ

No. Fini does not use customer data to train foundation models. Any per-customer learning happens only inside that customer’s environment and only with their written authorization. Fini’s LLM subprocessors are contractually barred from training on it. This commitment is in the DPA. See Data handling.
In the region you designate: the United States or the European Union. With EU data residency, data is stored and processed in the EU. Fini runs on Google Cloud. If you buy through Microsoft Marketplace, Fini can run on Azure in your own tenant, with Private Link, VNet support, customer-managed encryption keys, Entra ID and Conditional Access. See Data handling.
Fini supports single sign-on with Okta, Google, Slack and Microsoft Entra ID. The setup guide covers Okta step by step: Okta SSO.
Google Cloud (including Gemini) for hosting and AI, Microsoft Azure for Azure Marketplace deployments (including Azure AI Foundry and Azure OpenAI), Supabase as the managed database, OpenAI and Anthropic for LLM inference under enterprise agreements, PostHog for product analytics (usage metrics only), Sentry for error monitoring and logging, Stripe for billing, Linear for issue tracking, Google for email, and Langfuse for tracing. Fini gives 30 days’ notice of subprocessor changes under the DPA. See Data handling.
Within 72 hours, under the DPA.
No. An Action runs only when a Tool node in a published rule invokes it, and Intent Rule execution is deterministic: the same conversation context produces the same tree walk. You decide which Actions exist, which rules call them, and which agents those rules are assigned to. Every Action call is recorded in the AI Steps trace. See Rulebook.
Open the conversation in Inbox and click the light bulb icon on any Fini reply. The AI Steps sidebar shows Planning, Executed User Attributes, Executed Rule, Generate Answer, tag selection with reasoning, and Guardrails verdicts, in execution order.
Yes. You set your own retention period, and deletion removes all data. Delete through the Delete conversation and Bulk delete conversations endpoints, or by request. See Data handling.
Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. Design workflows so card numbers, CVVs and health details never need to enter the conversation: don’t ask customers for them, and route card actions through your payment provider via Actions. Configure Guardrails as an extra layer. See Data handling.
Yes. Customers can export audit logs. For reply-level reasoning, use the AI Steps trace in Inbox.
Yes. A VSA Full self-assessment is listed in the Trust Center. See also Security questionnaire.

Data handling, residency and model training

What Fini processes, where, for how long, and under which DPA terms.

SOC 2 Type II and ISO 27001

What Fini holds and how to request the reports.

PCI DSS

Fini’s PCI DSS Level 1 certification and how to keep card actions in your payment systems.

HIPAA and BAAs

Requesting a BAA and configuring Fini for protected health information.

Regulated industries: disputes and complaints

Capture, tag, escalate and audit complaint and dispute conversations.