How we protect your data

Security & trust

You're trusting Fini with your content and your customers' conversations. Here's how we look after them, stated plainly, without badges we haven't earned yet.

Our practices

Encryption

Encrypted in transit

Everything on fini.ai is served over HTTPS with HSTS. Customer data in the service is encrypted in transit and at rest.

Privacy

Your data stays yours

We don't sell data and don't use your content to train models for anyone else. AI providers are used through business APIs that don't train on that data.

Access

Least-privilege access

Only the people who need access to run the service have it, and your agent works only from the content and rules you give it.

Control

Actions with guardrails

Account and billing data is shown only after the customer confirms their email with a one-time code. Refunds wait for your one-click approval, and calls to your own API are read-only.

Retention

Deletion on request

Delete an agent or your account and its data is removed within 30 days.

Report

Responsible disclosure

Found a vulnerability? Email hello@fini.ai with "Security" in the subject. We respond within 2 business days.

Compliance

Fini is in early access and is not yet SOC 2 certified. It's on our roadmap, and we'll publish it here when it's done rather than before. We support GDPR and CCPA data requests today; see our Privacy Policy. Need a security questionnaire or a DPA? Contact us.

Infrastructure

The fini.ai website and app are served from Cloudflare's global network. The service's database and processing run on Supabase in the United States (AWS us-east-1), with data encrypted at rest. Keys for tools you connect are additionally encrypted with AES-256-GCM, with the key held outside the database. Email is delivered by Resend; business email runs on Google Workspace.

Keep reading