Security, Privacy & AI Use — at a glance
FIN Group serves SEC- and state-registered investment advisers, broker-dealers, private funds, and family offices. We hold ourselves to the same standards we help our clients meet. Everything you need for your CCO due-diligence file is on this page.
Infrastructure
Encryption
Access controls
Data residency
AI posture
How our software is built
Underlying certifications
Sub-processors
Every third-party vendor that may process FIN Group or client data is listed below. This list is kept current and is available for your outsourcing-rule and vendor due-diligence files.
| Vendor | Purpose | Data processed | Region | Certifications |
|---|---|---|---|---|
| Supabase (Lovable Cloud) | Application database, auth, file storage, edge functions | Client account + portal data, uploaded documents | US (AWS us-east-1 / us-west-1) | SOC 2 Type II, HIPAA-eligible, GDPR |
| Amazon Web Services (AWS) | Underlying compute, Postgres, S3 storage | All persisted data at rest | US (configurable) | SOC 1/2/3, ISO 27001, PCI-DSS, FedRAMP |
| Lovable (development platform & AI gateway) | AI-assisted application development environment, build/deploy pipeline, and the enterprise gateway our platforms call models through | Application source code and configuration; prompt text routed to model providers. No client production records used in development. | US | SOC 2 Type II |
| Cloudflare | CDN, DNS, TLS termination, WAF/DDoS protection, edge runtime for server functions | Request metadata in transit; no persistent storage of client records | Global edge, US origin | SOC 2 Type II, ISO 27001, PCI-DSS |
| Deno Deploy | Runtime for scheduled and event-driven backend functions | Payloads in transit during function execution | US (Cloudflare network layer) | SOC 2 Type II |
| GitHub (Microsoft) | Source control, code review history, and change/version records for our platforms | Application source code only — never client data | US | SOC 1/2/3, ISO 27001 |
| OpenAI (via enterprise API) | LLM inference for drafting, classification, summarization | Prompt text + context (no training, zero data retention) | US | SOC 2 Type II |
| Google (Gemini via Lovable AI Gateway) | LLM inference for drafting and analysis | Prompt text + context (no training) | US | SOC 2 Type II, ISO 27001 |
| Anthropic (Claude via gateway) | LLM inference for higher-reasoning tasks | Prompt text + context (no training) | US | SOC 2 Type II |
| Resend | Transactional & marketing email delivery | Recipient email, subject, body | US | SOC 2 Type II |
| Stripe | Payment processing (where applicable) | Billing contact, card tokens | US/Global | PCI-DSS Level 1, SOC 1/2 |
| Pipedrive | CRM for sales follow-up on inbound leads | Lead contact info & inquiry context | US/EU | SOC 2, GDPR |
| Zapier | Customer-configured workflow automation between our platforms and the firm's own apps (opt-in per firm) | Only the fields the firm chooses to route | US | SOC 2 Type II, GDPR |
| Microsoft Teams (webhook) | Internal notifications for inbound forms | Form submission summaries | US | SOC 2, ISO 27001 |
| Marketing distribution of our own content | Public posts only — no client data | US/EU | SOC 2, ISO 27001 |
Material changes to this list are reflected within 30 days. To be notified of changes, email support@fincompliance.io.
Commitments we make in writing
We will not sell, license, rent, or otherwise monetize client data.
We will not use client data to train foundation AI models — ours or anyone else's.
We will not deploy AI features that affect client deliverables without human compliance review.
We will not market AI capabilities we cannot demonstrate (no AI washing).
We will surface AI's role to your firm clearly enough that your CCO can document it.
We will provide a sub-processor change log and 30-day notice for material changes on request.
Need a full vendor DDQ packet?
We maintain a packaged due-diligence response covering security, BCP, AI use, sub-processors, and insurance — formatted for your outsourcing-rule (Rule 206(4)-11) file.