
Always on. Always secure.
Your data is encrypted, isolated, and never used to train models. Finrep runs the way your security team needs, including on-premises or in your private cloud.
Certified & compliant
Independent third-party certifications validate both the design and operational effectiveness of our controls, audited by independent firms and renewed through ongoing surveillance.
SOC 2 Type II
Security, Availability, and Confidentiality. Controls validated over time by an independent auditor.
ISO 27001
Full Information Security Management System covering risk, access, incident, and continuity governance.
GDPR-aligned
Data processing aligned to GDPR principles, with DPAs available on request.
Available on completionRun Finrep wherever your security team needs it
Four ways to run Finrep, from fully-managed SaaS to a fully on-premises install inside your own network. Every mode ships with the same encryption, access controls, and audit logging.
- 01
Hosted SaaS
Managed by Finrep on enterprise cloud (AWS and Azure) with geo-redundant encrypted backups. The fastest path to value, with zero infrastructure to run.
- 02
Single-tenant dedicated
An isolated instance with separate encryption keys, isolated database instances, and infrastructure-level separation for enterprise customers.
- 03
Private cloud (BYOC)
A dedicated deployment inside your own AWS, Azure, or GCP account. You own the cloud; we run and maintain Finrep for you.
- 04
On-premises
Run Finrep inside your own network with no public ingress, reachable over VPN. Your data never leaves your perimeter.
- Private network / VPN
- IP allow-listing
- SAML SSO
- Immutable audit logs
Encrypted at every layer
Industry-standard cryptography across the entire data lifecycle: at rest, in transit, in databases, and in backups.
AES-256 at rest
All databases, object storage, and backups encrypted with AES-256.
TLS 1.3 in transit
Every connection (client, service, and model) encrypted with TLS 1.3.
Field-level encryption
Sensitive fields encrypted independently of the underlying database.
Encrypted, geo-redundant backups
Daily encrypted backups replicated across regions; recovery drilled quarterly.
Secure by default, across every model
Routes through leading AI providers under contractual no-train terms, with gateway-managed failover, role-based access, and full audit logging.
Internal AI gateway
All model traffic routes through our gateway, which manages provider selection and failover.
Role-based model access
Who can invoke which model is governed by RBAC and fully audited.
TLS 1.3 on every model call
No model request leaves the platform unencrypted.
Full AI request logging
Every model invocation is logged with user, prompt metadata, and provider.
You stay in control of your data
Retention, governance, and authentication are all configurable to your policy and regulatory needs.
Data retention
Configurable retention to match your policy, including zero data retention on request.
Data governance
Real-time visibility into who is accessing your data, and when.
SSO & authentication
SAML 2.0 and OIDC single sign-on put authentication fully in your control.
Documents
Request any document below. We'll verify your work email and share it after a brief review.
SOC 2 Type II report
ReportIndependent audit of our security, availability, and confidentiality controls.
ISO 27001 certificate
ReportOur ISMS certification and scope.
Penetration test summary
ReportSummary of our most recent independent penetration test.
Architecture & data-flow diagram
DiagramHow data flows through Finrep, including AI provider routing.
Security, answered
No. Your data is processed solely to serve your requests, under enterprise agreements that prohibit training and limit retention. It is never used to train foundation models.
Production data is encrypted at rest (AES-256) in managed databases on enterprise cloud infrastructure across AWS and Azure, with geo-redundant encrypted backups.
Yes. Finrep supports on-premises installation and private cloud hosting, with private network/VPN support, IP allow-listing, SAML SSO, and immutable audit logs. Your data can remain within your network.
We route through Anthropic, Azure OpenAI, and Google Vertex AI, all under contractual no-train terms, limited retention, and SOC 2 compliance, mediated by our internal AI gateway.
We follow a documented incident response framework with defined severity levels, containment and remediation procedures, contractual customer notification obligations, and a post-incident review.
Use any "Request report" button on this page. We verify your work email and share the document after a brief review.
Retention is configurable to your DPA. On contract termination, primary data is deleted within 30 days and backups within 90 days, with deletion confirmation available on request.


