Fini (usefini.com) holds SOC 2 Type II and ISO/IEC 27001, supports GDPR and CCPA obligations, and is HIPAA-compliant with a BAA available. Customer data is encrypted with AES-256 at rest and TLS 1.2+ in transit, stays in your choice of US or EU region, and is never used to train foundation models. This page is written for security, privacy and procurement reviewers. It summarizes Fini’s posture, tells you where to get the evidence (audit reports, pen-test report, DPA), and lists the controls your own team configures inside the product. Fini’s policies and reports live in the Trust Center; this page links to them rather than restating them.

Posture at a glance

The Trust Center risk profile also classifies Fini at Data Access Level: Internal and Impact Level: Moderate. Use those values if your vendor-risk tool asks for the vendor’s self-assessed tier.
To confirm (internal, remove before publish): The Trust Center lists a Cyber Insurance document, but its Cyber Insurance entry reads “We are working on an insurance policy with cyber coverage.” Is a cyber insurance policy in force today? If not, remove the cyber insurance row and mentions on this page.

Getting the evidence

Fini’s Trust Center at security.usefini.com is the single place for security documentation. Public sections cover product security, data security, app security, infrastructure, endpoint, network and corporate security, legal, and policies. Sensitive documents are gated and released on request.
1

Open the Trust Center

Go to security.usefini.com and click Get access (or Start your security review).
2

Request the documents you need

The featured documents are the Pentest Report, ISO/IEC 27001, SOC 2, Cyber Insurance and Data Processing Agreement. The Reports section also lists a Network Diagram, and Self-Assessments include a VSA Full questionnaire.
3

Ask follow-up questions

Use Ask for information in the Trust Center for anything not covered by the documents. Report a suspected vulnerability with Report issue.
Start with the VSA Full self-assessment and the SOC 2 report before sending your own questionnaire. Many questions in a standard vendor security questionnaire are answered there already, so your follow-up list is shorter.
Legal terms are published on usefini.com: For legal and privacy questions, contact legal@usefini.com.

Controls your team configures

Certifications cover how Fini runs its platform. The controls below are the ones you own inside your workspace. A security review is stronger when it covers both.
Guardrails are not a fail-closed security boundary. If a check errors or times out, the original reply can be sent unchanged. Treat Guardrails as one layer alongside Reply Rules, Rulebook design and Test Suite coverage, and review per-check verdicts in AI Steps. See Guardrails.

Reviewer FAQ

No. Customer data is never used to train foundation models, and Fini’s LLM subprocessors are contractually barred from training on it. This commitment is in the DPA. See Data handling.
In the region you designate: the United States or the European Union. Fini runs on Google Cloud. If you buy through Microsoft Marketplace, Fini can run on Azure in your own tenant, with Private Link, VNet support, customer-managed encryption keys, Entra ID and Conditional Access. See Data handling.
Fini supports SAML 2.0 single sign-on. The setup guide covers Okta step by step: Okta SSO. SSO and SAML are included on every plan.
To confirm (internal, remove before publish): Which other SAML identity providers are supported today (for example Microsoft Entra ID, Google Workspace, OneLogin, Ping), and is SCIM provisioning available? The live docs only document Okta.
Exhibit A of the DPA lists Google Cloud, Supabase, OpenAI and Anthropic. Fini’s published subprocessors also include PostHog, Sentry, Stripe, Linear and Langfuse. Fini gives 30 days’ notice of subprocessor changes.
To confirm (internal, remove before publish): The Trust Center has a Subprocessors entry, but its subprocessor section is hidden with the placeholder “We are working on our subprocessors. Please contact us for more details.” Where is the full, current subprocessor list published for customers? Until it is live, point reviewers to DPA Exhibit A.
Within 72 hours, under the DPA.
No. An Action runs only when a Tool node in a published rule invokes it, and Intent Rule execution is deterministic: the same conversation context produces the same tree walk. You decide which Actions exist, which rules call them, and which agents those rules are assigned to. Every Action call is recorded in the AI Steps trace. See Rulebook.
Open the conversation in Inbox and click the light bulb icon on any Fini reply. The AI Steps sidebar shows Planning, Executed User Attributes, Executed Rule, Generate Answer, tag selection with reasoning, and Guardrails verdicts, in execution order.
Yes, through the Delete conversation and Bulk delete conversations endpoints, or by request. Default retention and deletion on termination are covered in Data handling.
See PCI DSS. Whatever the attestation status, we recommend that card numbers and security codes never pass through a support conversation, and the page explains how to configure that.
Yes. A VSA Full self-assessment is listed in the Trust Center. See also Security questionnaire.

Data handling, residency and model training

What Fini processes, where, for how long, and under which DPA terms.

SOC 2 Type II and ISO 27001

What Fini holds and how to request the reports.

HIPAA and BAAs

Requesting a BAA and configuring Fini for protected health information.

Regulated industries: disputes and complaints

Capture, tag, escalate and audit complaint and dispute conversations.