Fini (usefini.com) holds a SOC 2 Type II report and ISO/IEC 27001 certification, and both are listed under Compliance in the Fini Trust Center. Request the SOC 2 report and the ISO/IEC 27001 certificate at security.usefini.com; they are shared on request rather than published openly.

What each one tells you

For a plain-language explanation of each framework, see the usefini.com glossary entries for SOC 2 Type II and ISO 27001.

Request the reports

1

Open the Trust Center

Go to security.usefini.com and click Get access.
2

Select the documents

Choose SOC 2 and ISO/IEC 27001. Most reviews also need the Pentest Report, the Data Processing Agreement and the VSA Full self-assessment, so request them in the same pass.
3

Ask for anything missing

Use Ask for information for a bridge letter, a specific control description, or a question about an exception in the report.

Scope

To confirm (internal, remove before publish): For the SOC 2 Type II report: auditor (CPA firm), report period start and end dates, Trust Services Criteria in scope (Security only, or also Availability, Confidentiality, Processing Integrity, Privacy), systems and environments in scope (Google Cloud production, Azure Marketplace deployments, the dashboard, the API), and whether a bridge letter is available for the gap since the period end. For ISO/IEC 27001: certification body, certificate number, standard version (2013 or 2022), scope statement, issue and expiry dates, and whether the Statement of Applicability can be shared. Also confirm whether Trust Center access requires an NDA.
When you receive the reports, check three things against your use of Fini:
  1. The period and dates. A SOC 2 Type II report covers a fixed window. If that window ended months ago, ask for a bridge letter.
  2. The systems in scope. Confirm the report covers the deployment you will use (Fini on Google Cloud in your US or EU region, or Fini on Azure through Microsoft Marketplace).
  3. Complementary user entity controls. SOC 2 reports list controls the customer is expected to operate. Map each one to how you run your Fini workspace, for example SSO and user assignment, API key management, and how you configure what the agent may say and do. See Controls your team configures.

Security overview

Full posture table and reviewer FAQ.

Data handling

Residency, encryption, subprocessors, retention and DPA terms.

Security questionnaire

Answers to common vendor security questions.

PCI DSS

PCI status and keeping card data out of conversations.