Finnoto handles financial data across orders, settlements, bank credits and books. We protect it with encryption, least-privilege access, full audit logging and continuous monitoring - and operate to recognised security frameworks. This page summarises our controls; detailed reports are available under NDA.
Hosted on AWS infrastructure with data residency in India. Network isolation, security groups and managed patching at the platform layer.
Data encrypted in transit (TLS) and at rest (AES-256), with keys managed via a managed key-management service. Secrets are never stored in plaintext.
Role-based access control (RBAC), least-privilege defaults, maker-checker on sensitive actions, and SSO support. Production access is restricted and logged.
Full audit trails on data and money-movement actions, with continuous logging and monitoring to detect and investigate anomalies.
We operate to SOC 2 Type II and ISO 27001:2022 control frameworks. Independent audit reports and certification status are available under NDA - please ask your Finnoto contact.
We sign Data Processing Agreements (DPAs) and align our handling with India's data-protection regime. See our Data Policy and Privacy Policy.
We use a limited set of vetted subprocessors (e.g. cloud hosting and infrastructure providers). The current list is available on request.
Documented incident-response process with defined severity levels and customer notification commitments. Report concerns to security@finnoto.com.
Automated backups and recovery procedures to protect against data loss, with monitoring of platform availability.
Enterprise prospects and customers can request our security package - including audit report availability, certification status, the subprocessor list, hosting details, encryption model, access-control design, incident-response summary and a Data Processing Agreement - under NDA. Email security@finnoto.com or speak to your Finnoto contact.
Compliance status note: certification and audit statuses are confirmed on request and may apply to specific systems or time periods. Where a certification is in progress, we will say so. This page describes the controls we operate; it is not itself a certificate.
Need our security package, a DPA, or a vendor assessment completed? We'll get you what you need.
Contact us