Security & Data Protection
Finsyt is built for institutional research, where trust is the product. Enterprise-grade controls, tenant isolation, and responsible AI — your data is yours, and it never trains anyone's model.
SECURITY PILLARS
The controls that protect your research surface.
No Training on Your Data
Customer prompts, uploaded documents, and AI outputs are never used to train Finsyt's or any third-party model. All inference runs through contractual no-train endpoints.
Encryption Everywhere
TLS 1.2+ for every request in transit. AES-256 at rest for documents, embeddings, databases, and backups. Keys are managed by our cloud provider's KMS with regular rotation.
Data Residency
Customer data is stored in US (us-east) regions by default. EU residency is available for Enterprise customers on request, with no cross-region replication of customer content.
Isolation & Tenant Separation
Every workspace is logically isolated with row-level tenant scoping enforced in the data layer. Vector indexes, document stores, and audit logs are partitioned per workspace.
Data Retention & Deletion
You control your data. Documents and chat history can be deleted on demand and are purged from primary storage and backups within 30 days. Account deletion removes all customer content.
Compliance & Certifications
We are pursuing SOC 2 Type 2 and ISO 27001 attestations and operate to the controls expected of an enterprise SaaS handling sensitive financial research.
Authentication & SSO
Email + password with optional MFA today. SAML 2.0 / OIDC SSO and SCIM provisioning are on the Enterprise roadmap, with enforced SSO and just-in-time provisioning.
Access Control
Role-based access control across workspaces, teams, and projects. Detailed audit logs of authentication, document access, and admin actions, exportable for Enterprise customers.
Vendor & Data Provider Posture
We diligence every subprocessor and data vendor for security, retention, and AI-training posture. We only use providers whose terms align with our customer commitments.
CERTIFICATIONS & COMPLIANCE
Honest status, no theater.
We publish where we stand on each framework. We do not claim certifications we have not earned.
Controls implementation and observation period underway. Report request available to qualified prospects under NDA.
ISMS scoping in progress. Targeted certification following SOC 2 attestation.
DPA available on request. Data minimization, lawful basis, and subject-rights workflows in production.
SUBPROCESSORS
Every vendor we touch your data with.
The third parties Finsyt relies on, what they do, and what data flows to them. Market-data vendors only receive ticker queries — never your prompts or documents.
| Provider | Purpose | Data shared |
|---|---|---|
| Amazon Web Services | Application hosting, storage, and managed databases | All customer content (encrypted at rest), service logs |
| Clerk | Authentication, MFA, and session management | Account identifiers, emails, hashed credentials |
| OpenAI / Anthropic / Google (AI providers) | Server-side LLM inference for research workflows | Prompts and document context for the duration of the request. Contractual no-training endpoints. |
| Polygon.io | Market data (prices, fundamentals, reference data) | Ticker queries only — no customer content |
| Financial Modeling Prep (FMP) | Fundamentals and statements | Ticker queries only — no customer content |
| Yahoo Finance | Reference and historical pricing | Ticker queries only — no customer content |
| EODHD | End-of-day pricing and macro data | Ticker queries only — no customer content |
| Alpha Vantage | Technical indicators and supplementary data | Ticker queries only — no customer content |
| SEC EDGAR | Public filings ingestion | Public filing identifiers — no customer content |
| PostHog | Product analytics and event telemetry | De-identified usage events, account IDs |
Material changes to this list are communicated to customers in advance per our DPA.
RESPONSIBLE AI
Your prompts stay yours.
Prompts, uploaded documents, generated outputs, and feedback are never used to train Finsyt's or any third-party model. All AI providers are accessed via contractual no-train endpoints.
AI calls are made server-side from Finsyt's backend. Provider API keys never live in your browser, and we strip identifiers from telemetry to AI providers.
Generative outputs are grounded in retrieved primary sources. Every fact and figure links to the underlying document so you can verify before you trade.
Finsyt is a research copilot, not an autonomous trading agent. Outputs are advisory and surfaced with their sources for analyst review.