Security

Built for data you are trusted with

Your clients trust you with their finances. These are the controls that protect that trust, described as they actually work.

Firm-by-firm separation

Every record belongs to one firm, and every request is checked against the firms the signed-in person belongs to. A link to another firm's page is refused, not redirected.

Roles that mean something

Admin, member, read-only, client and employee roles are enforced on the server for every action — hiding a button is never the only protection.

Support only with your consent

FIINO staff cannot open your firm unless a firm admin grants access, for a fixed time, view-only or with changes. You can revoke it at any moment.

Audit trails

Changes to your records and every FIINO support session are logged. Staff actions in our own console are logged too.

Sign-in protection

Passwords are stored as salted hashes, sign-in attempts are rate-limited, and two-factor authentication is available to every user and required for FIINO staff.

Encrypted in transit

All traffic to FIINO uses HTTPS. Session cookies are HTTP-only and marked secure.

Data protection

Under UK GDPR your firm is the controller of your clients' personal data and FIINO acts as your processor. Our data processing agreement sets out what we do with it, and our privacy notice covers the data we hold about you as a customer.

FIINO includes tools to handle subject access requests and to export your records at any time.

Reporting a vulnerability

If you believe you have found a security issue, please tell us privately through our contact page before disclosing it, and give us reasonable time to fix it.