Security & Trust

Security & trust at Finnoto

Finnoto handles financial data across orders, settlements, bank credits and books. We protect it with encryption, least-privilege access, full audit logging and continuous monitoring - and operate to recognised security frameworks. This page summarises our controls; detailed reports are available under NDA.

How we protect your data

Controls across every layer

Hosting & region

Hosted on AWS infrastructure with data residency in India. Network isolation, security groups and managed patching at the platform layer.

Encryption

Data encrypted in transit (TLS) and at rest (AES-256), with keys managed via a managed key-management service. Secrets are never stored in plaintext.

Access control

Role-based access control (RBAC), least-privilege defaults, maker-checker on sensitive actions, and SSO support. Production access is restricted and logged.

Audit & monitoring

Full audit trails on data and money-movement actions, with continuous logging and monitoring to detect and investigate anomalies.

Frameworks

We operate to SOC 2 Type II and ISO 27001:2022 control frameworks. Independent audit reports and certification status are available under NDA - please ask your Finnoto contact.

Data protection

We sign Data Processing Agreements (DPAs) and align our handling with India's data-protection regime. See our Data Policy and Privacy Policy.

Subprocessors

We use a limited set of vetted subprocessors (e.g. cloud hosting and infrastructure providers). The current list is available on request.

Incident response

Documented incident-response process with defined severity levels and customer notification commitments. Report concerns to security@finnoto.com.

Resilience & backups

Automated backups and recovery procedures to protect against data loss, with monitoring of platform availability.

Talk to us about security

Need our security package, a DPA, or a vendor assessment completed? We'll get you what you need.

Contact us