Fini’s certifications, encryption, data residency, hosting and legal terms in one table, plus the product controls your team configures and where to get audit reports.
Fini (usefini.com) holds SOC 2 Type II and ISO/IEC 27001, supports GDPR and CCPA obligations, and is HIPAA-compliant with a BAA available. Customer data is encrypted with AES-256 at rest and TLS 1.2+ in transit, stays in your choice of US or EU region, and is never used to train foundation models.This page is written for security, privacy and procurement reviewers. It summarizes Fini’s posture, tells you where to get the evidence (audit reports, pen-test report, DPA), and lists the controls your own team configures inside the product. Fini’s policies and reports live in the Trust Center; this page links to them rather than restating them.
Listed as a Trust Center document; see the note below
Trust Center
The Trust Center risk profile also classifies Fini at Data Access Level: Internal and Impact Level: Moderate. Use those values if your vendor-risk tool asks for the vendor’s self-assessed tier.
To confirm (internal, remove before publish): The Trust Center lists a Cyber Insurance document, but its Cyber Insurance entry reads “We are working on an insurance policy with cyber coverage.” Is a cyber insurance policy in force today? If not, remove the cyber insurance row and mentions on this page.
Fini’s Trust Center at security.usefini.com is the single place for security documentation. Public sections cover product security, data security, app security, infrastructure, endpoint, network and corporate security, legal, and policies. Sensitive documents are gated and released on request.
1
Open the Trust Center
Go to security.usefini.com and click Get access (or Start your security review).
2
Request the documents you need
The featured documents are the Pentest Report, ISO/IEC 27001, SOC 2, Cyber Insurance and Data Processing Agreement. The Reports section also lists a Network Diagram, and Self-Assessments include a VSA Full questionnaire.
3
Ask follow-up questions
Use Ask for information in the Trust Center for anything not covered by the documents. Report a suspected vulnerability with Report issue.
Start with the VSA Full self-assessment and the SOC 2 report before sending your own questionnaire. Many questions in a standard vendor security questionnaire are answered there already, so your follow-up list is shorter.
Certifications cover how Fini runs its platform. The controls below are the ones you own inside your workspace. A security review is stronger when it covers both.
Control
What it does
Where
Single sign-on
Your team signs into the Fini dashboard with your identity provider. Only users assigned to the SAML app can sign in, so offboarding in your IdP removes access.
Workspace keys carry read, write or both. Keys are shown once, can be revoked individually, and revocation is immediate. Keep write off for export-only integrations.
Checks run on every generated reply before delivery: Confidential attributes (values of selected user attributes must not appear in replies), Banned terms, URL allowlist, AI disclosure, Internal reasoning leak, and up to 10 Custom rule checks.
Decide per conversation whether the agent sends a Direct Reply, leaves an Internal Comment for your team only, or sends No Reply. The stricter behavior always wins.
Actions run only when a Tool node in a published Intent Rule or Business Rule invokes them, so the agent cannot call an API outside a rule you built and tested.
Every Fini reply has an AI Steps trace: knowledge retrieved, rules and nodes executed, user attributes loaded, tags applied, guardrail verdicts and the model’s reasoning.
Guardrails are not a fail-closed security boundary. If a check errors or times out, the original reply can be sent unchanged. Treat Guardrails as one layer alongside Reply Rules, Rulebook design and Test Suite coverage, and review per-check verdicts in AI Steps. See Guardrails.
No. Customer data is never used to train foundation models, and Fini’s LLM subprocessors are contractually barred from training on it. This commitment is in the DPA. See Data handling.
Where is our data stored?
In the region you designate: the United States or the European Union. Fini runs on Google Cloud. If you buy through Microsoft Marketplace, Fini can run on Azure in your own tenant, with Private Link, VNet support, customer-managed encryption keys, Entra ID and Conditional Access. See Data handling.
Which identity providers work for SSO?
Fini supports SAML 2.0 single sign-on. The setup guide covers Okta step by step: Okta SSO. SSO and SAML are included on every plan.
To confirm (internal, remove before publish): Which other SAML identity providers are supported today (for example Microsoft Entra ID, Google Workspace, OneLogin, Ping), and is SCIM provisioning available? The live docs only document Okta.
Who are Fini's subprocessors?
Exhibit A of the DPA lists Google Cloud, Supabase, OpenAI and Anthropic. Fini’s published subprocessors also include PostHog, Sentry, Stripe, Linear and Langfuse. Fini gives 30 days’ notice of subprocessor changes.
To confirm (internal, remove before publish): The Trust Center has a Subprocessors entry, but its subprocessor section is hidden with the placeholder “We are working on our subprocessors. Please contact us for more details.” Where is the full, current subprocessor list published for customers? Until it is live, point reviewers to DPA Exhibit A.
Can the AI agent take actions we haven't approved?
No. An Action runs only when a Tool node in a published rule invokes it, and Intent Rule execution is deterministic: the same conversation context produces the same tree walk. You decide which Actions exist, which rules call them, and which agents those rules are assigned to. Every Action call is recorded in the AI Steps trace. See Rulebook.
How do we audit what the agent said and why?
Open the conversation in Inbox and click the light bulb icon on any Fini reply. The AI Steps sidebar shows Planning, Executed User Attributes, Executed Rule, Generate Answer, tag selection with reasoning, and Guardrails verdicts, in execution order.
See PCI DSS. Whatever the attestation status, we recommend that card numbers and security codes never pass through a support conversation, and the page explains how to configure that.