Security

What we hold, what we never hold

FIN-TECHAI reads public chain data and the wallet identifiers you send us. We never take custody of funds, never request a withdrawal permission, and never hold a private key. Everything below is what we do with what is left.

Never held

Private keys, seed phrases, withdrawal permissions

Encrypted

AES-256 at rest, TLS 1.3 in transit, no exceptions

SOC 2 Type II

Audit in progress — report expected Q4 2026

12 months

Default evidence retention, then hard deletion

Data

What we store and for how long

DataWhy we hold itRetentionDeletion
Wallet addresses you screenTo serve the score and its evidence trail on later review12 months defaultOn request or contract end
Score and reason historyAudit defensibility — proving what you were told, when12 months, up to 7 years contractedHard delete, including backups, within 30 days
API keysAuthenticationUntil you revokeImmediate on revocation
Request logsDebugging, rate limiting, abuse detection30 daysAutomatic rolling deletion
Your ledger data (Ledger Mind)Reconciliation matchingContract termHard delete within 30 days of termination
Private keys, seedsNever collected

Public chain data is public. Retaining our own copy of it is not a privacy decision about your customers; retaining the link between your account and the addresses you screened is, and that is what the table above governs.

Controls

How the platform is protected

Infrastructure

  • Single-tenant database schemas per customer
  • Private networking; no public database endpoints
  • Infrastructure as code with peer-reviewed changes
  • Automated dependency and container scanning

Access

  • SSO and hardware-key MFA mandatory for all staff
  • Least privilege, time-bound production access
  • Every production access session recorded and reviewed
  • Quarterly access recertification

Assurance

  • SOC 2 Type II audit in progress, Q4 2026
  • Annual third-party penetration test
  • Continuous vulnerability scanning
  • Disclosure programme at security@fin-techai.com
Subprocessors

Who else touches the data

This list is maintained here and changes are announced to customers thirty days before they take effect.

SubprocessorPurposeDataRegion
Amazon Web ServicesPrimary hosting and storageAll platform dataeu-central-1, us-east-1
CloudflareEdge, WAF, DDoS mitigationRequest metadataGlobal edge
DatadogObservabilityLogs and metrics, addresses redactedEU
StripeCard payment processingBilling contact and card dataUS, EU
Chainalysis, TRMSupplementary sanctions and attribution feedsAddresses queriedUS
Incident response

If something goes wrong

Severity is assigned within one hour of detection. Customers materially affected are notified within 24 hours of confirmation, in writing, with what we know and what we do not yet know. A post-incident review is published to affected customers within ten business days.

We do not use a status page as a substitute for telling you directly. Both happen.

security@fin-techai.com · PGP key on request

Report a vulnerability to security@fin-techai.com. We acknowledge within one business day and will not pursue good-faith researchers.
Sub-processor changes are announced 30 days ahead. You may object; for material objections we will discuss an alternative or an exit.
No vendor can make you compliant. Our controls protect the data you send us — your own obligations as a regulated entity remain yours.

Need the security pack?

Questionnaire responses, pen-test summary, DPA and the SOC 2 bridge letter are available under NDA.