Skip to main content
Security & trust

Built forthe regulated few.

SOC 2, HIPAA BAAs, GDPR, ISO 27001 — compliance isn't a checkbox, it's how the platform was designed. From key management to data residency.

Book a demo
SOC 2Type II — in progress
HIPAABAA on request
GDPR& DPDP-compliant
256-bitAES at rest + in transit

Security primitives

Compliance isthe floor, not the ceiling.

Voice is regulated. Healthcare, finance, insurance, legal — Finn was built to run there from day one.

01

Encryption in transit and at rest

AES-256 at rest, TLS 1.3 in transit. Recordings, transcripts, PII — all encrypted by default.

02

Data residency

Pick where your data lives. US, India, Singapore, Australia, UK, and EU regions available — no data leaves the chosen geography.

03

Audit trails

Every API call, every config change, every data access — logged, immutable, exportable.

04

PII redaction

Auto-redact card numbers, SSNs, account IDs from transcripts. Custom regex for industry-specific patterns.

05

Role-based access

Granular permissions per user, per workspace. SSO via SAML or OIDC. SCIM provisioning for enterprise.

06

Compliance frameworks

SOC 2 Type II, HIPAA BAAs, GDPR DPA, ISO 27001 — documentation available under NDA.

encryption + access

In transit and at rest. Defense in depth.

AES-256 at rest. TLS 1.3 in transit. Per-workspace KMS keys. SSO via SAML or OIDC. SCIM provisioning. Role-based access control granular down to the field level.

  • AES-256 at rest, TLS 1.3 in transit
  • Per-workspace encryption keys via KMS
  • SAML / OIDC SSO + SCIM auto-provisioning
  • Field-level RBAC with audit trail

compliance frameworks

SOC 2. HIPAA BAA. GDPR. ISO 27001.

SOC 2 Type II audit in progress; documentation available under NDA. We've shipped into healthcare, fintech, insurance, and legal — the regulated workloads were the design constraint, not an afterthought.

  • SOC 2 Type II — audit in progress
  • HIPAA BAA on request, healthcare-ready
  • GDPR + India DPDP — region-aware
  • ISO 27001 + NIST CSF mapped

data residency

Your data, in your geography.

Pick where your data lives — US, India, Singapore, Australia, UK, or EU regions available today. No data leaves the chosen region. Per-workspace residency, even within a single tenant.

  • US, India, Singapore, Australia, UK, EU regions live now
  • Per-workspace residency boundaries
  • Audit trails of every data access
  • Right-to-deletion + export on demand

Trust, not promises

Audit-grade,from call one.

Security is what you ship, not what you say. Every Finn deployment carries the same controls the regulated incumbents use — without their procurement cycle.

Book a demo30-min trial · No card

Audited + compliant

SOC 2 Type IIHIPAA BAAGDPRISO 27001DPDPNIST CSF