Security, Privacy & AI Use — at a glance
FIN Group serves SEC- and state-registered investment advisers, broker-dealers, private funds, and family offices. We hold ourselves to the same standards we help our clients meet. Everything you need for your CCO due-diligence file is on this page.
Infrastructure
Encryption
Access controls
Data residency
AI posture
Underlying certifications
Sub-processors
Every third-party vendor that may process FIN Group or client data is listed below. This list is kept current and is available for your outsourcing-rule and vendor due-diligence files.
| Vendor | Purpose | Data processed | Region | Certifications |
|---|---|---|---|---|
| Supabase (Lovable Cloud) | Application database, auth, file storage, edge functions | Client account + portal data, uploaded documents | US (AWS us-east-1 / us-west-1) | SOC 2 Type II, HIPAA-eligible, GDPR |
| Amazon Web Services (AWS) | Underlying compute, Postgres, S3 storage | All persisted data at rest | US (configurable) | SOC 1/2/3, ISO 27001, PCI-DSS, FedRAMP |
| OpenAI (via enterprise API) | LLM inference for drafting, classification, summarization | Prompt text + context (no training, zero data retention) | US | SOC 2 Type II |
| Google (Gemini via Lovable AI Gateway) | LLM inference for drafting and analysis | Prompt text + context (no training) | US | SOC 2 Type II, ISO 27001 |
| Anthropic (Claude via gateway) | LLM inference for higher-reasoning tasks | Prompt text + context (no training) | US | SOC 2 Type II |
| Resend | Transactional & marketing email delivery | Recipient email, subject, body | US | SOC 2 Type II |
| Stripe | Payment processing (where applicable) | Billing contact, card tokens | US/Global | PCI-DSS Level 1, SOC 1/2 |
| Pipedrive | CRM for sales follow-up on inbound leads | Lead contact info & inquiry context | US/EU | SOC 2, GDPR |
| Microsoft Teams (webhook) | Internal notifications for inbound forms | Form submission summaries | US | SOC 2, ISO 27001 |
| Marketing distribution of our own content | Public posts only — no client data | US/EU | SOC 2, ISO 27001 |
Material changes to this list are reflected within 30 days. To be notified of changes, email support@fincompliance.io.
Commitments we make in writing
We will not sell, license, rent, or otherwise monetize client data.
We will not use client data to train foundation AI models — ours or anyone else's.
We will not deploy AI features that affect client deliverables without human compliance review.
We will not market AI capabilities we cannot demonstrate (no AI washing).
We will surface AI's role to your firm clearly enough that your CCO can document it.
We will provide a sub-processor change log and 30-day notice for material changes on request.
Need a full vendor DDQ packet?
We maintain a packaged due-diligence response covering security, BCP, AI use, sub-processors, and insurance — formatted for your outsourcing-rule (Rule 206(4)-11) file.