Built for
the regulated few.
SOC 2, HIPAA BAAs, GDPR, ISO 27001 — compliance isn't a checkbox, it's how the platform was designed. From key management to data residency.
Security primitives
Compliance is
the floor, not the ceiling.
Voice is regulated. Healthcare, finance, insurance, legal — Finn was built to run there from day one.
Encryption in transit and at rest
AES-256 at rest, TLS 1.3 in transit. Recordings, transcripts, PII — all encrypted by default.
Data residency
Pick where your data lives. US, India, Singapore, Australia, UK, and EU regions available — no data leaves the chosen geography.
Audit trails
Every API call, every config change, every data access — logged, immutable, exportable.
PII redaction
Auto-redact card numbers, SSNs, account IDs from transcripts. Custom regex for industry-specific patterns.
Role-based access
Granular permissions per user, per workspace. SSO via SAML or OIDC. SCIM provisioning for enterprise.
Compliance frameworks
SOC 2 Type II, HIPAA BAAs, GDPR DPA, ISO 27001 — documentation available under NDA.
encryption + access
In transit and at rest. Defense in depth.
AES-256 at rest. TLS 1.3 in transit. Per-workspace KMS keys. SSO via SAML or OIDC. SCIM provisioning. Role-based access control granular down to the field level.
- AES-256 at rest, TLS 1.3 in transit
- Per-workspace encryption keys via KMS
- SAML / OIDC SSO + SCIM auto-provisioning
- Field-level RBAC with audit trail
compliance frameworks
SOC 2. HIPAA BAA. GDPR. ISO 27001.
SOC 2 Type II audit in progress; documentation available under NDA. We've shipped into healthcare, fintech, insurance, and legal — the regulated workloads were the design constraint, not an afterthought.
- SOC 2 Type II — audit in progress
- HIPAA BAA on request, healthcare-ready
- GDPR + India DPDP — region-aware
- ISO 27001 + NIST CSF mapped
data residency
Your data, in your geography.
Pick where your data lives — US, India, Singapore, Australia, UK, or EU regions available today. No data leaves the chosen region. Per-workspace residency, even within a single tenant.
- US, India, Singapore, Australia, UK, EU regions live now
- Per-workspace residency boundaries
- Audit trails of every data access
- Right-to-deletion + export on demand
Trust, not promises
Audit-grade,
from call one.
Security is what you ship, not what you say. Every Finn deployment carries the same controls the regulated incumbents use — without their procurement cycle.
Audited + compliant
More platform