Security at Fintegrity
A plain-language overview of how we protect the data that runs through our platform. This page is a summary for anyone evaluating Fintegrity — Clients under contract receive fuller technical and security detail as part of due diligence.
Security built into how we operate
These are the practices we apply across our platform and infrastructure today.
All traffic to and from our platform is encrypted using industry-standard TLS. Stored data is encrypted at rest using our infrastructure provider’s encryption capabilities.
Access to production systems and customer data is restricted by role and limited to what each person needs to do their job. Multi-factor authentication is required for administrative access, and access to customer data is logged.
Fintegrity runs on established cloud infrastructure, with physical and network security managed by our hosting provider. We walk prospective Clients through our specific hosting and data-residency setup directly, as part of due diligence.
Every decision and state change our platform produces is written to an append-only audit trail — the same evidence architecture we build for our Clients’ compliance teams applies to how we run the business.
Working toward ISO 27001 alignment
- We are aligning our security practices with ISO/IEC 27001 controls.
- Formal third-party certification is on our roadmap — it has not been achieved yet.
- We'll update this page the moment that status changes.
Found a vulnerability?
If you believe you've found a security issue in our platform or website, tell us before telling anyone else. Email contact@getfintegrity.comwith what you found and how to reproduce it, and give us a reasonable window to investigate and fix it before any public disclosure. Please don't access, modify, or exfiltrate data that isn't yours while testing.
Questions about our security practices?
If you're evaluating Fintegrity as a Client and need more detail than this page covers, we're happy to walk through it directly.