Skip to main content
Fini (usefini.com) is SOC 2 Type II compliant and ISO/IEC 27001:2022 certified, and both are listed under Compliance in the Fini Trust Center. Request the SOC 2 report and the ISO/IEC 27001 certificate at security.usefini.com; they are shared on request rather than published openly.

What each one tells you

For a plain-language explanation of each framework, see the usefini.com glossary entries for SOC 2 Type II and ISO 27001.

Request the reports

1

Open the Trust Center

Go to security.usefini.com and click Get access.
2

Select the documents

Choose SOC 2 and ISO/IEC 27001. Most reviews also need the Pentest Report, the Data Processing Agreement and the VSA Full self-assessment, so request them in the same pass.
3

Ask for anything missing

Use Ask for information for a bridge letter, a specific control description, or a question about an exception in the report.

Reviewing the reports

When you receive the reports, check three things against your use of Fini:
  1. The period and dates. A SOC 2 Type II report covers a fixed window. If that window ended months ago, ask for a bridge letter.
  2. The systems in scope. Confirm the report covers the deployment you will use (Fini on Google Cloud in your US or EU region, or Fini on Azure through Microsoft Marketplace).
  3. Complementary user entity controls. SOC 2 reports list controls the customer is expected to operate. Map each one to how you run your Fini workspace, for example SSO and user assignment, API key management, and how you configure what the agent may say and do. See Controls your team configures.

Security overview

Full posture table and reviewer FAQ.

Data handling

Residency, encryption, subprocessors, retention and DPA terms.

Security questionnaire

Answers to common vendor security questions.

PCI DSS

Fini’s PCI DSS Level 1 certification and how to request the attestation.

HIPAA and BAAs

Requesting a BAA and configuring Fini for protected health information.