How we protect your data

Security & trust

You're trusting Fini with your content and your customers' conversations. Here's how we look after them, stated plainly, without badges we haven't earned yet.

Our practices

Encryption

Encrypted in transit

Everything on fini.ai is served over HTTPS with HSTS. Customer data in the service is encrypted in transit and at rest.

Privacy

Your data stays yours

We don't sell data and don't use your content to train models for anyone else. AI providers are used through business APIs that don't train on that data.

Access

Least-privilege access

Only the people who need access to run the service have it, and actions your agent takes are limited to the ones you allow.

Control

Actions with guardrails

Your agent confirms with the customer before changing anything and logs every action so you can review it.

Retention

Deletion on request

Delete an agent or your account and its data is removed within 30 days.

Report

Responsible disclosure

Found a vulnerability? Email hello@fini.ai with "Security" in the subject. We respond within 2 business days.

Compliance

Fini is in early access and is not yet SOC 2 certified. It's on our roadmap, and we'll publish it here when it's done rather than before. We support GDPR and CCPA data requests today; see our Privacy Policy. Need a security questionnaire or a DPA? Contact us.

Infrastructure

The fini.ai website is hosted on Netlify's global edge network. Business email runs on Google Workspace.

Keep reading