What each one tells you
For a plain-language explanation of each framework, see the usefini.com glossary entries for SOC 2 Type II and ISO 27001.
Request the reports
1
Open the Trust Center
Go to security.usefini.com and click Get access.
2
Select the documents
Choose SOC 2 and ISO/IEC 27001. Most reviews also need the Pentest Report, the Data Processing Agreement and the VSA Full self-assessment, so request them in the same pass.
3
Ask for anything missing
Use Ask for information for a bridge letter, a specific control description, or a question about an exception in the report.
Scope
When you receive the reports, check three things against your use of Fini:- The period and dates. A SOC 2 Type II report covers a fixed window. If that window ended months ago, ask for a bridge letter.
- The systems in scope. Confirm the report covers the deployment you will use (Fini on Google Cloud in your US or EU region, or Fini on Azure through Microsoft Marketplace).
- Complementary user entity controls. SOC 2 reports list controls the customer is expected to operate. Map each one to how you run your Fini workspace, for example SSO and user assignment, API key management, and how you configure what the agent may say and do. See Controls your team configures.
Related
Security overview
Full posture table and reviewer FAQ.
Data handling
Residency, encryption, subprocessors, retention and DPA terms.
Security questionnaire
Answers to common vendor security questions.
PCI DSS
PCI status and keeping card data out of conversations.

