> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usefini.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SOC 2 Type II and ISO 27001

> Fini is SOC 2 Type II compliant and ISO/IEC 27001:2022 certified; request both reports through the Trust Center at security.usefini.com.

Fini (usefini.com) is SOC 2 Type II compliant and ISO/IEC 27001:2022 certified, and both are listed under Compliance in the Fini Trust Center. Request the SOC 2 report and the ISO/IEC 27001 certificate at [security.usefini.com](https://security.usefini.com/); they are shared on request rather than published openly.

## What each one tells you

| | SOC 2 Type II | ISO/IEC 27001:2022 |
| - | - | - |
| What it is | An independent auditor's report on how Fini's controls were designed and how they operated over a review period | Certification that Fini operates an information security management system (ISMS) meeting the ISO/IEC 27001:2022 standard |
| What reviewers use it for | Testing specific controls (access, change management, monitoring, incident response) and reading any exceptions the auditor noted | Confirming that security is run as a managed program with risk assessment, policies and continual improvement |
| How to get it | Request the **SOC 2** document in the [Trust Center](https://security.usefini.com/) | Request the **ISO/IEC 27001** document in the [Trust Center](https://security.usefini.com/) |

For a plain-language explanation of each framework, see the usefini.com glossary entries for [SOC 2 Type II](https://www.usefini.com/glossary/what-is-soc-2-type-ii) and [ISO 27001](https://www.usefini.com/glossary/what-is-iso-27001).

## Request the reports

<Steps>
  <Step title="Open the Trust Center">
    Go to [security.usefini.com](https://security.usefini.com/) and click **Get access**.
  </Step>

  <Step title="Select the documents">
    Choose **SOC 2** and **ISO/IEC 27001**. Most reviews also need the **Pentest Report**, the **Data Processing Agreement** and the **VSA Full** self-assessment, so request them in the same pass.
  </Step>

  <Step title="Ask for anything missing">
    Use **Ask for information** for a bridge letter, a specific control description, or a question about an exception in the report.
  </Step>
</Steps>

## Reviewing the reports

When you receive the reports, check three things against your use of Fini:

1. **The period and dates.** A SOC 2 Type II report covers a fixed window. If that window ended months ago, ask for a bridge letter.
2. **The systems in scope.** Confirm the report covers the deployment you will use (Fini on Google Cloud in your US or EU region, or Fini on Azure through Microsoft Marketplace).
3. **Complementary user entity controls.** SOC 2 reports list controls the customer is expected to operate. Map each one to how you run your Fini workspace, for example SSO and user assignment, API key management, and how you configure what the agent may say and do. See [Controls your team configures](/en/security/overview#controls-your-team-configures).

## Related

<CardGroup cols={2}>
  <Card title="Security overview" icon="shield-halved" href="/en/security/overview">
    Full posture table and reviewer FAQ.
  </Card>

  <Card title="Data handling" icon="database" href="/en/security/data-handling">
    Residency, encryption, subprocessors, retention and DPA terms.
  </Card>

  <Card title="Security questionnaire" icon="clipboard-check" href="/en/evaluate/security-questionnaire">
    Answers to common vendor security questions.
  </Card>

  <Card title="PCI DSS" icon="credit-card" href="/en/security/pci-dss">
    Fini's PCI DSS Level 1 certification and how to request the attestation.
  </Card>

  <Card title="HIPAA and BAAs" icon="notes-medical" href="/en/security/hipaa">
    Requesting a BAA and configuring Fini for protected health information.
  </Card>
</CardGroup>


## Related topics

- [Security overview](/en/security/overview.md)
- [Billing FAQ](/en/billing/billing-faq.md)
- [Fini FAQ](/en/faq.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.