Skip to main content
    Trust Center · Updated August 2026

    Security, Privacy & AI Use — at a glance

    FIN Group serves SEC- and state-registered investment advisers, broker-dealers, private funds, and family offices. We hold ourselves to the same standards we help our clients meet. Everything you need for your CCO due-diligence file is on this page.

    Infrastructure

    Hosted on Supabase / AWS in US regions by default. Postgres + S3, both encrypted at rest with AES-256.

    Encryption

    TLS 1.2+ in transit. AES-256 at rest. Secrets in encrypted vaults. Passwords bcrypt-hashed. Signed URLs for document downloads.

    Access controls

    Row-Level Security on every table. Service-role operations restricted to edge functions. TOTP MFA available for client portals.

    Data residency

    US-based AWS regions by default (us-east-1 / us-west-1). Region pinning available on request for state, SEC, or non-US compliance needs.

    AI posture

    Enterprise gateways with zero data retention. No client data used for model training. See the AI Disclosure.

    How our software is built

    Our platforms are developed with AI-assisted engineering under a documented SDLC: named owner per release, human code review, staged testing, version-controlled change history, and no client production data in development or test environments. See AI Disclosure.

    Underlying certifications

    Supabase SOC 2 Type II · AWS SOC 1/2/3, ISO 27001, PCI-DSS, FedRAMP · HIPAA-eligible infrastructure available.

    Sub-processors

    Every third-party vendor that may process FIN Group or client data is listed below. This list is kept current and is available for your outsourcing-rule and vendor due-diligence files.

    VendorPurposeData processedRegionCertifications
    Supabase (Lovable Cloud)Application database, auth, file storage, edge functionsClient account + portal data, uploaded documentsUS (AWS us-east-1 / us-west-1)SOC 2 Type II, HIPAA-eligible, GDPR
    Amazon Web Services (AWS)Underlying compute, Postgres, S3 storageAll persisted data at restUS (configurable)SOC 1/2/3, ISO 27001, PCI-DSS, FedRAMP
    Lovable (development platform & AI gateway)AI-assisted application development environment, build/deploy pipeline, and the enterprise gateway our platforms call models throughApplication source code and configuration; prompt text routed to model providers. No client production records used in development.USSOC 2 Type II
    CloudflareCDN, DNS, TLS termination, WAF/DDoS protection, edge runtime for server functionsRequest metadata in transit; no persistent storage of client recordsGlobal edge, US originSOC 2 Type II, ISO 27001, PCI-DSS
    Deno DeployRuntime for scheduled and event-driven backend functionsPayloads in transit during function executionUS (Cloudflare network layer)SOC 2 Type II
    GitHub (Microsoft)Source control, code review history, and change/version records for our platformsApplication source code only — never client dataUSSOC 1/2/3, ISO 27001
    OpenAI (via enterprise API)LLM inference for drafting, classification, summarizationPrompt text + context (no training, zero data retention)USSOC 2 Type II
    Google (Gemini via Lovable AI Gateway)LLM inference for drafting and analysisPrompt text + context (no training)USSOC 2 Type II, ISO 27001
    Anthropic (Claude via gateway)LLM inference for higher-reasoning tasksPrompt text + context (no training)USSOC 2 Type II
    ResendTransactional & marketing email deliveryRecipient email, subject, bodyUSSOC 2 Type II
    StripePayment processing (where applicable)Billing contact, card tokensUS/GlobalPCI-DSS Level 1, SOC 1/2
    PipedriveCRM for sales follow-up on inbound leadsLead contact info & inquiry contextUS/EUSOC 2, GDPR
    ZapierCustomer-configured workflow automation between our platforms and the firm's own apps (opt-in per firm)Only the fields the firm chooses to routeUSSOC 2 Type II, GDPR
    Microsoft Teams (webhook)Internal notifications for inbound formsForm submission summariesUSSOC 2, ISO 27001
    LinkedInMarketing distribution of our own contentPublic posts only — no client dataUS/EUSOC 2, ISO 27001

    Material changes to this list are reflected within 30 days. To be notified of changes, email support@fincompliance.io.

    Commitments we make in writing

    We will not sell, license, rent, or otherwise monetize client data.

    We will not use client data to train foundation AI models — ours or anyone else's.

    We will not deploy AI features that affect client deliverables without human compliance review.

    We will not market AI capabilities we cannot demonstrate (no AI washing).

    We will surface AI's role to your firm clearly enough that your CCO can document it.

    We will provide a sub-processor change log and 30-day notice for material changes on request.

    Need a full vendor DDQ packet?

    We maintain a packaged due-diligence response covering security, BCP, AI use, sub-processors, and insurance — formatted for your outsourcing-rule (Rule 206(4)-11) file.