Security · SOC 2 & GDPR

Your financial data, protected

FinnAccountings is GDPR and UK GDPR compliant, with SOC 2 Type II controls across security, availability, and confidentiality. Trust is non-negotiable when you're handling tax, payroll, and business finances.

GDPR compliantUK GDPR compliantSOC 2 Type II compliantPrivate document vault

Private by design

Your files stay sealed — even from us

Most finance tools store your PDFs where a cloud admin could open them. We lock every upload before it is saved, so browsing storage only shows scrambled data — not your receipts, contracts, or tax packs.

When you ask the AI for help, FinnAccountings unlocks only what that answer needs — for that moment — then your documents stay sealed again.

  • Uploads locked before they are stored
  • Cloud browsers see gibberish, not your files
  • AI unlocks only what it needs, when you ask
  • Your account is the key — not a shared backdoor

Locked before it leaves your session

Receipts, invoices, and the documents you upload for AI advice are scrambled before they are saved. What sits in storage is unreadable without your account unlocking it for you.

Access controls

Role-based permissions, least privilege, session management, and audit logs track access to sensitive data. Staff access requires MFA.

Secure infrastructure

Hosted on AWS with private networking, WAF protection, CloudTrail-aligned logging, automated patching, infrastructure as code, and continuous monitoring.

GDPR & UK GDPR compliant

We act as a data processor for your business data. A public DPA, subprocessors list, cookie consent, and in-app data export / account deletion support data subject rights.

SOC 2 Type II compliant

Our controls map to SOC 2 Type II Trust Services Criteria for security, availability, and confidentiality — including change management, vendor management, and incident response.

User rights built in

Export your personal data or delete your account from Settings → Privacy & data. Data subject requests are also handled at [email protected] within 30 days.

Security practices

  • Regular penetration testing and vulnerability scanning
  • Employee security training and background checks where appropriate
  • Incident response plan with 72-hour breach notification target
  • Open Banking connections use read-only access with your explicit consent
  • AI providers process data under DPAs — Customer Data is never used to train public models
  • Uploaded documents are locked at rest — not left readable in plain storage
  • PR reviews, CI/CD, and dependency scanning for change control
  • Defined retention: logs ~90 days; deleted accounts purged after export window
  • Annual third-party security reviews

Legal documents: Privacy Policy, DPA, Subprocessors, Cookie Policy. For security enquiries or to report a vulnerability, use our contact form or email security@finnaccounts.com.

14-day free trial · No credit card

Ready to prepare your next VAT period?

Organise transactions and receipts, flag what is missing, and prepare VAT and bookkeeping packs for Ireland and the UK — with you in control before anything is shared or filed.