Fini (usefini.com) holds SOC 2 Type II and ISO 27001, supports GDPR and CCPA, is HIPAA-compliant with a BAA available, encrypts customer data with AES-256 at rest and TLS 1.2+ in transit, and never uses customer data to train foundation models. This page answers the questions security and procurement teams ask most often, with a source for every answer, so you can fill most of a SIG Lite or CAIQ style questionnaire without waiting on a call. The Fini Trust Center is the primary source for security documentation. Reports, policies, and the completed vendor security questionnaire listed there are shared on request through the Trust Center’s Get access flow. Where an answer below says “Available via the Trust Center on request”, the Trust Center lists that document.
How to use this page. Copy answers directly into your questionnaire, and attach the documents you request from the Trust Center as evidence. Contractual commitments (breach notice, subprocessor notice, transfer mechanisms) are set by the Data Processing Addendum and your MSA; if this page and a signed agreement ever differ, the agreement wins.
Search or filter every answer here. The sourced tables below carry the same answers with links to each source document.

Certifications and assessments

Data protection and residency

AI and model use

Access control and authentication

Logging, monitoring, and vulnerability management

Incident response and business continuity

People and corporate security

Customers can also request Fini’s compliance reports (SOC 2, ISO 27001, GDPR) under the Trust Center’s customer audit rights. For privacy and legal questions, contact legal@usefini.com.
To confirm (internal, remove before publish):
  1. PCI DSS (row 6). The usefini.com homepage claims PCI DSS Level 1, but the Trust Center lists only GDPR, ISO/IEC 27001, and SOC 2. What is the exact PCI status (level, attestation type, scope), and is an AOC available to share?
  2. SSO (row 25). The Trust Center marks “SSO Support” as in progress, while the docs describe live Okta SAML 2.0 SSO. Update the Trust Center, and confirm whether IdPs other than Okta (for example Microsoft Entra ID or Google) are supported.
  3. MFA (row 26). Does the Trust Center MFA entry cover customer dashboard users or only Fini employees? Can a customer enforce MFA for non-SSO logins?
  4. EU residency and LLM inference (rows 12 and 21). The subprocessor data embedded in the Trust Center page lists OpenAI and Anthropic with location “US”. For a customer who designates EU residency, does LLM inference stay in the EU (for example through Microsoft Azure), or is it processed in the US under the SCCs?
  5. Model training (row 20). The Trust Center’s privacy entry says “When we train our custom models for our customers we remove any personally identifiable information from data.” Does Fini train per-customer custom models on Customer Data? If so, the “never used to train” wording needs a precise qualifier (foundation or shared models).
  6. Cyber insurance (row 40). The Trust Center lists a Cyber Insurance document, but its explanation reads “We are working on an insurance policy with cyber coverage.” Is a policy in force, and what is the coverage?
  7. Subprocessor list (row 14). The Trust Center’s subprocessor section is hidden (“We are working on our subprocessors. Please contact us for more details.”), and its Subprocessors tile shows logos for OpenAI, Supabase, Amazon Web Services (AWS), Microsoft Azure and Google Cloud. AWS appears in no other Fini source. Is AWS a subprocessor, and what does Azure process outside Marketplace deployments? Publish the full list so row 14 can point to it.
  8. Log retention (row 30). How long are audit logs and conversation traces retained, and can customers export audit logs?

Security overview

How Fini secures customer data, and where each document lives.

Data handling, residency and model training

Residency, retention, subprocessors, and model training in depth.

Questions to ask an AI support vendor

Evaluation questions beyond security, with Fini’s answers.

RFP fact sheet

Copy-ready company and product facts for RFPs.