Skip to main content
Trust Center

How we protect your financial data

Where we are today, what we ship, and what we're working toward. We prefer honest language to over-claiming: we only publish compliance and security details we can actually back up.

Compliance posture

SOC 2 Type II

In progress

Auditor engaged Q3 2026. Type I expected Q4 2026; Type II expected Q1 2027.

Expected: Q1 2027

GDPR

Live

DPA template available on request. Sub-processor list below.

Expected: Live since 2024

CCPA

Live

Privacy policy + data-deletion workflow.

Expected: Live since 2024

ISO 42001 (AI Management Systems)

In progress

Readiness review on Q1 2027 roadmap. We do not claim certification until we have one.

Expected: Q1 2027 review

HIPAA

Not in scope

Not in scope. We do not handle PHI today. Contact us before signing if your workload requires HIPAA.

Expected: n/a

FedRAMP

Not in scope

Not authorized today. No government-cloud deployment.

Expected: n/a

Sub-processors

Sub-processorPurposeTheir compliance
NeonPostgres hostingSOC 2 Type II
CloudflareR2 object storage + CDNSOC 2 Type II
Auth0AuthenticationSOC 2 Type II, ISO 27001, ISO 27018
RailwayApplication hostingSOC 2 Type II
OpenRouterLLM routingSOC 2 Type II
SentryApplication monitoringSOC 2 Type II
ResendTransactional emailSOC 2 Type II

Self-serve resources

Contact

Status as of Aug 19, 2026. Last reviewed by the Security Lead. Next scheduled review: end of Q3 2026. We will publish material security incidents within 72 hours at status.finadvantage.online.

Trust Center | FinAdvantage