Limited spots available. Join the waitlist for FREE exclusive early access and a special deal.Sign up now →
Trust Center

Your financial data is safe with Finistack

We hold ourselves to the same security and privacy standards used by financial institutions and large enterprises. See below controls to understand exactly how we protect your information.
✓244 controls passing · Updated as of Oct 2026
12 passing

SOC 2 Type II

The U.S. standard for how service companies keep customer data secure, available and confidential.
6 passing

GDPR

Europe’s privacy law, covering how personal data is collected, protected and handled after a breach.
48 passing

PCI DSS v4.0

The payment card industry’s rules for protecting cardholder and account data.
84 passing

Microsoft Cloud Security Benchmark

Microsoft’s best-practice security baseline for cloud services, including AI security.

How we protect you

We’ve grouped hundreds of technical checks into nine areas that matter to you. A green check means the control is in place and passed its most recent automated review.

Data Protection & Encryption

Your financial information is scrambled with strong encryption whenever it is stored or sent, so it is unreadable to anyone without permission.

✓ 7 controls passing

Encrypted in transit

Data moving between your device and Finistack travels over encrypted connections.
MCSBPCI DSS

Encrypted at rest by default

Everything we store, including databases and file storage, is encrypted automatically.
MCSBPCI DSS

Secure key management

Encryption keys are kept in a protected vault and rotated under strict rules.
MCSB

Managed security certificates

Website and service certificates are issued, tracked and renewed securely.
MCSB

Sensitive data monitoring

Unusual attempts to reach sensitive data are detected and flagged.
MCSB

Protected account data

Any stored account numbers are secured wherever they are kept.
PCI DSS

Hardened storage and databases

Our storage accounts and databases pass Finistack’s own security policies.
Finistack policy

Privacy & Your Personal Data

We collect only what we need, protect it carefully and tell you promptly if anything ever goes wrong.

✓ 7 controls passing

Privacy by design

Privacy protections are built into Finistack from the start and switched on by default.
GDPR

Secure processing

Personal data is handled with security measures matched to its sensitivity.
GDPR

Clear accountability

Finistack takes responsibility, as data controller, for how your data is used.
GDPR

Vetted data processors

Any partner that handles data for us is bound by the same protections.
GDPR

Breach notification to regulators

If a breach occurs, we notify the relevant authority within required timeframes.
GDPR

Breach notification to you

If your data is affected, we tell you directly and explain what to do.
GDPR

Need-to-know sharing

Information moves only to people and systems authorized to see it.
SOC 2

Account & Access Security

Only the right people can get in, and only to what they need. That applies to you and to every member of our team.

✓ 8 controls passing

Strong sign-in protection

Multi-factor authentication protects both user and administrator accounts.
MCSBPCI DSS

Central identity system

All access runs through one protected identity system with single sign-on.
MCSB

Least-privilege access

People get the minimum access their role needs, and nothing more.
MCSBSOC 2PCI DSS

No permanent admin rights

Administrator access is separated, limited and granted only when needed.
MCSB

Secrets kept out of sight

Passwords and API keys are never stored in code or exposed.
MCSB

Access lifecycle reviews

Access is granted, reviewed and removed as team members join, move or leave.
MCSB

Conditional access

Sign-ins are checked against location, device and risk before access is allowed.
MCSB

Emergency access plan

A tightly controlled break-glass process exists for urgent situations.
MCSB

Infrastructure & Network Security

The systems that run Finistack are walled off, filtered and watched to keep attackers out.

✓ 8 controls passing

Segmented network

Our systems are divided into isolated zones so a problem in one can’t spread.
MCSBPCI DSS

Web application firewall

Malicious web traffic is filtered before it reaches Finistack.
MCSBPCI DSS

DDoS protection

Defenses absorb floods of traffic meant to knock services offline.
MCSB

Intrusion detection & prevention

Suspicious network activity is spotted and blocked automatically.
MCSB

Insecure protocols disabled

Outdated, unsafe connection methods are found and turned off.
MCSB

Anti-malware protection

Modern anti-malware and endpoint detection run on our systems and stay up to date.
MCSBPCI DSSSOC 2

Secure data centers

Physical access to servers is controlled by Microsoft Azure’s secured facilities.
PCI DSS

Locked-down AI services

Our AI services accept connections only from an approved allow list.
Finistack policy

Monitoring & Incident Response

We watch for threats around the clock and have a tested plan to act fast if something happens.

✓ 6 controls passing

Continuous threat detection

Automated tools look for attacks across our systems and sign-ins, 24/7.
MCSBSOC 2

Centralized security logs

Security events are collected in one place and kept for investigations.
MCSBPCI DSS

Audit logging on key systems

Networks, databases, AI services and key vaults all record audit trails.
Finistack policy

Documented response plan

A written incident plan defines who does what when an alert fires.
MCSBSOC 2PCI DSS

Fast triage and containment

Incidents are investigated, prioritized and contained, with automation where possible.
MCSBSOC 2

Lessons learned

After every incident we review what happened and keep evidence to improve.
MCSB

Secure Development

Security is built into how we design, write and release software, not bolted on afterward.

✓ 7 controls passing

Threat modeling

New features are reviewed for security risks before they are built.
MCSB

Software supply chain checks

Third-party code and libraries are vetted before we use them.
MCSB

Automated code scanning

Code is tested for security flaws automatically before each release.
MCSBPCI DSS

Controlled changes

Changes to software, data and infrastructure are reviewed and approved.
SOC 2

Regular vulnerability scans

Weaknesses are found, prioritized and fixed quickly.
MCSBPCI DSS

Penetration testing

Security specialists regularly try to break in so we can fix gaps first.
MCSBPCI DSS

Secure configuration baselines

Every system must match an approved secure setup, and drift is corrected.
MCSBPCI DSS

Backup & Business Continuity

Your data is backed up automatically and we regularly prove we can restore it.

✓ 5 controls passing

Automated backups

Data is backed up automatically on a regular schedule.
MCSB

Protected backups

Backups are encrypted and shielded from tampering or deletion.
MCSB

Backup monitoring

Every backup job is monitored so failures are caught right away.
MCSB

Tested restores

We regularly test restoring from backup to make sure it works.
MCSB

Incident recovery

Defined steps get services back to normal after a security event.
SOC 2

Responsible AI

Fini, our AI finance assistant, runs with guardrails that keep its answers safe and its access limited.

✓ 6 controls passing

Content filtering

Several layers of filtering screen what goes into and comes out of the AI.
MCSB

Built-in safety instructions

Fini follows safety rules designed to keep its responses appropriate.
MCSB

Limited AI permissions

AI agents can only reach the data and actions they truly need.
MCSB

Human in the loop

People stay in control of important decisions; the AI does not act alone.
MCSB

AI activity monitoring

AI usage is monitored to detect misuse or unexpected behavior.
MCSB

Continuous AI red teaming

We regularly test Fini against attempts to trick or misuse it.
MCSB

Governance & Policies

Clear policies, ownership and risk management keep security a company-wide priority.

✓ 6 controls passing

Information security policy

A written policy guides how everyone at Finistack protects information.
PCI DSSSOC 2

Defined security roles

Security responsibilities and accountability are clearly assigned.
MCSBSOC 2

Formal risk management

Risks are identified, evaluated and managed on an ongoing basis.
PCI DSS

Asset inventory

We keep an up-to-date inventory of our systems and their risks.
MCSB

Approved services only

Only reviewed and approved cloud services and applications are allowed.
MCSB

Vendor access approval

Outside support staff need explicit approval before accessing anything.
MCSB

Control status is generated from continuous automated assessments in Microsoft Defender for Cloud against each standard. Some controls, such as physical data center security, are provided by Microsoft Azure under a shared responsibility model. Updated as of Oct 2026.

Built on Microsoft Azure

Finistack runs on Microsoft Azure, so your data sits in data centers with 24/7 physical security, redundant power and independent audits. Microsoft secures the buildings and hardware. We secure everything we build on top: your account, your data and our AI assistant, Fini.
Proud to collaborate with Microsoft for Startups

Have a security question?

Our team is happy to walk you or your IT department through how Finistack keeps your data safe.