Skip to main content
    Trust Center · Updated August 2026

    Security, Privacy & AI Use — at a glance

    FIN Group serves SEC- and state-registered investment advisers, broker-dealers, private funds, and family offices. We hold ourselves to the same standards we help our clients meet. Everything you need for your CCO due-diligence file is on this page.

    Infrastructure

    Hosted on Supabase / AWS in US regions by default. Postgres + S3, both encrypted at rest with AES-256.

    Encryption

    TLS 1.2+ in transit. AES-256 at rest. Secrets in encrypted vaults. Passwords bcrypt-hashed. Signed URLs for document downloads.

    Access controls

    Row-Level Security on every table. Service-role operations restricted to edge functions. TOTP MFA available for client portals.

    Data residency

    US-based AWS regions by default (us-east-1 / us-west-1). Region pinning available on request for state, SEC, or non-US compliance needs.

    AI posture

    Enterprise gateways with zero data retention. No client data used for model training. See the AI Disclosure.

    Underlying certifications

    Supabase SOC 2 Type II · AWS SOC 1/2/3, ISO 27001, PCI-DSS, FedRAMP · HIPAA-eligible infrastructure available.

    Sub-processors

    Every third-party vendor that may process FIN Group or client data is listed below. This list is kept current and is available for your outsourcing-rule and vendor due-diligence files.

    VendorPurposeData processedRegionCertifications
    Supabase (Lovable Cloud)Application database, auth, file storage, edge functionsClient account + portal data, uploaded documentsUS (AWS us-east-1 / us-west-1)SOC 2 Type II, HIPAA-eligible, GDPR
    Amazon Web Services (AWS)Underlying compute, Postgres, S3 storageAll persisted data at restUS (configurable)SOC 1/2/3, ISO 27001, PCI-DSS, FedRAMP
    OpenAI (via enterprise API)LLM inference for drafting, classification, summarizationPrompt text + context (no training, zero data retention)USSOC 2 Type II
    Google (Gemini via Lovable AI Gateway)LLM inference for drafting and analysisPrompt text + context (no training)USSOC 2 Type II, ISO 27001
    Anthropic (Claude via gateway)LLM inference for higher-reasoning tasksPrompt text + context (no training)USSOC 2 Type II
    ResendTransactional & marketing email deliveryRecipient email, subject, bodyUSSOC 2 Type II
    StripePayment processing (where applicable)Billing contact, card tokensUS/GlobalPCI-DSS Level 1, SOC 1/2
    PipedriveCRM for sales follow-up on inbound leadsLead contact info & inquiry contextUS/EUSOC 2, GDPR
    Microsoft Teams (webhook)Internal notifications for inbound formsForm submission summariesUSSOC 2, ISO 27001
    LinkedInMarketing distribution of our own contentPublic posts only — no client dataUS/EUSOC 2, ISO 27001

    Material changes to this list are reflected within 30 days. To be notified of changes, email support@fincompliance.io.

    Commitments we make in writing

    We will not sell, license, rent, or otherwise monetize client data.

    We will not use client data to train foundation AI models — ours or anyone else's.

    We will not deploy AI features that affect client deliverables without human compliance review.

    We will not market AI capabilities we cannot demonstrate (no AI washing).

    We will surface AI's role to your firm clearly enough that your CCO can document it.

    We will provide a sub-processor change log and 30-day notice for material changes on request.

    Need a full vendor DDQ packet?

    We maintain a packaged due-diligence response covering security, BCP, AI use, sub-processors, and insurance — formatted for your outsourcing-rule (Rule 206(4)-11) file.