TRUST · SECURITY · PRIVACY

Security & Data Protection

Finsyt is built for institutional research, where trust is the product. Enterprise-grade controls, tenant isolation, and responsible AI — your data is yours, and it never trains anyone's model.

SECURITY PILLARS

The controls that protect your research surface.

Certified

No Training on Your Data

Customer prompts, uploaded documents, and AI outputs are never used to train Finsyt's or any third-party model. All inference runs through contractual no-train endpoints.

Certified

Encryption Everywhere

TLS 1.2+ for every request in transit. AES-256 at rest for documents, embeddings, databases, and backups. Keys are managed by our cloud provider's KMS with regular rotation.

In progress

Data Residency

Customer data is stored in US (us-east) regions by default. EU residency is available for Enterprise customers on request, with no cross-region replication of customer content.

Certified

Isolation & Tenant Separation

Every workspace is logically isolated with row-level tenant scoping enforced in the data layer. Vector indexes, document stores, and audit logs are partitioned per workspace.

Certified

Data Retention & Deletion

You control your data. Documents and chat history can be deleted on demand and are purged from primary storage and backups within 30 days. Account deletion removes all customer content.

In progress

Compliance & Certifications

We are pursuing SOC 2 Type 2 and ISO 27001 attestations and operate to the controls expected of an enterprise SaaS handling sensitive financial research.

Roadmap

Authentication & SSO

Email + password with optional MFA today. SAML 2.0 / OIDC SSO and SCIM provisioning are on the Enterprise roadmap, with enforced SSO and just-in-time provisioning.

In progress

Access Control

Role-based access control across workspaces, teams, and projects. Detailed audit logs of authentication, document access, and admin actions, exportable for Enterprise customers.

Certified

Vendor & Data Provider Posture

We diligence every subprocessor and data vendor for security, retention, and AI-training posture. We only use providers whose terms align with our customer commitments.

CERTIFICATIONS & COMPLIANCE

Honest status, no theater.

We publish where we stand on each framework. We do not claim certifications we have not earned.

In progress
SOC 2 Type 2

Controls implementation and observation period underway. Report request available to qualified prospects under NDA.

Roadmap
ISO 27001

ISMS scoping in progress. Targeted certification following SOC 2 attestation.

Certified
GDPR

DPA available on request. Data minimization, lawful basis, and subject-rights workflows in production.

Need our SOC 2 report or DPA?

Available to qualified prospects and customers under NDA.

SUBPROCESSORS

Every vendor we touch your data with.

The third parties Finsyt relies on, what they do, and what data flows to them. Market-data vendors only receive ticker queries — never your prompts or documents.

ProviderPurposeData shared
Amazon Web ServicesApplication hosting, storage, and managed databasesAll customer content (encrypted at rest), service logs
ClerkAuthentication, MFA, and session managementAccount identifiers, emails, hashed credentials
OpenAI / Anthropic / Google (AI providers)Server-side LLM inference for research workflowsPrompts and document context for the duration of the request. Contractual no-training endpoints.
Polygon.ioMarket data (prices, fundamentals, reference data)Ticker queries only — no customer content
Financial Modeling Prep (FMP)Fundamentals and statementsTicker queries only — no customer content
Yahoo FinanceReference and historical pricingTicker queries only — no customer content
EODHDEnd-of-day pricing and macro dataTicker queries only — no customer content
Alpha VantageTechnical indicators and supplementary dataTicker queries only — no customer content
SEC EDGARPublic filings ingestionPublic filing identifiers — no customer content
PostHogProduct analytics and event telemetryDe-identified usage events, account IDs

Material changes to this list are communicated to customers in advance per our DPA.

RESPONSIBLE AI

Your prompts stay yours.

No training on customer content

Prompts, uploaded documents, generated outputs, and feedback are never used to train Finsyt's or any third-party model. All AI providers are accessed via contractual no-train endpoints.

Server-side proxied inference

AI calls are made server-side from Finsyt's backend. Provider API keys never live in your browser, and we strip identifiers from telemetry to AI providers.

Grounded answers, sentence-level citations

Generative outputs are grounded in retrieved primary sources. Every fact and figure links to the underlying document so you can verify before you trade.

Human-in-the-loop by default

Finsyt is a research copilot, not an autonomous trading agent. Outputs are advisory and surfaced with their sources for analyst review.

RESPONSIBLE DISCLOSURE

Report a vulnerability

We welcome reports from security researchers. Please email us with reproduction steps and we will respond within two business days. We do not pursue legal action against good-faith research conducted under our policy.