FIN-TECHAI reads public chain data and the wallet identifiers you send us. We never take custody of funds, never request a withdrawal permission, and never hold a private key. Everything below is what we do with what is left.
Private keys, seed phrases, withdrawal permissions
AES-256 at rest, TLS 1.3 in transit, no exceptions
Audit in progress — report expected Q4 2026
Default evidence retention, then hard deletion
| Data | Why we hold it | Retention | Deletion |
|---|---|---|---|
| Wallet addresses you screen | To serve the score and its evidence trail on later review | 12 months default | On request or contract end |
| Score and reason history | Audit defensibility — proving what you were told, when | 12 months, up to 7 years contracted | Hard delete, including backups, within 30 days |
| API keys | Authentication | Until you revoke | Immediate on revocation |
| Request logs | Debugging, rate limiting, abuse detection | 30 days | Automatic rolling deletion |
| Your ledger data (Ledger Mind) | Reconciliation matching | Contract term | Hard delete within 30 days of termination |
| Private keys, seeds | — | Never collected | — |
Public chain data is public. Retaining our own copy of it is not a privacy decision about your customers; retaining the link between your account and the addresses you screened is, and that is what the table above governs.
This list is maintained here and changes are announced to customers thirty days before they take effect.
| Subprocessor | Purpose | Data | Region |
|---|---|---|---|
| Amazon Web Services | Primary hosting and storage | All platform data | eu-central-1, us-east-1 |
| Cloudflare | Edge, WAF, DDoS mitigation | Request metadata | Global edge |
| Datadog | Observability | Logs and metrics, addresses redacted | EU |
| Stripe | Card payment processing | Billing contact and card data | US, EU |
| Chainalysis, TRM | Supplementary sanctions and attribution feeds | Addresses queried | US |
Severity is assigned within one hour of detection. Customers materially affected are notified within 24 hours of confirmation, in writing, with what we know and what we do not yet know. A post-incident review is published to affected customers within ten business days.
We do not use a status page as a substitute for telling you directly. Both happen.
security@fin-techai.com · PGP key on request
Questionnaire responses, pen-test summary, DPA and the SOC 2 bridge letter are available under NDA.