Trust & Security

Built to protect every Audit Engagement

Your engagement data is protected by design - encrypted, access-controlled, and never used to train shared AI models.

Governance

How we govern access

to your data

1.
Access to systems and customer information is limited to authorized users with a legitimate business need and appropriate permissions.
2.
Security controls are layered across identity, applications, infrastructure and data so protection does not depend on any single safeguard.
3.
Security controls, vulnerabilities and relevant events are reviewed as the platform, threat environment and regulatory expectations evolve.
4.
Security and privacy requirements are considered throughout product development, infrastructure changes and platform operations.

Security and Compliance at Finspectors

Our security program is built around recognized assurance and privacy requirements relevant to audit firms and enterprise customers.

Protection

Every layer,

protected.

Identity & Authentication
Finspectors supports SAML-based Single Sign-On and Multi-Factor Authentication for secure user authentication. Privileged cloud access can be protected using identity-aware controls.
Role-Based Access Controls
Permissions are governed by role and engagement so users only access the information and functionality relevant to their responsibilities.
Data Residency & Resilience
Customer data can be hosted within supported regional environments, with backup and recovery controls designed to protect availability and resilience.
Encryption & Key Protection
Customer information is protected using encryption in transit and at rest, with managed key controls across supported cloud infrastructure.
Infrastructure Isolation
Service perimeters and cloud access controls help restrict unauthorized access and reduce the risk of sensitive information leaving approved environments.
Auditability & Monitoring
Key user, administrative and system activities are logged to support traceability, monitoring and investigation. Relevant engagement actions remain reviewable within the platform.

Responsible use of AI

Your data stays yours,

even when AI is involved.

No Training on Customer Data

Customer data is not used to train shared or public foundation models. Where managed models are used, customer information is processed under the applicable provider and contractual controls.

Controlled Data Access

AI operates only on information made available within the authorized engagement and user context, subject to the platform’s access controls.

Human Oversight

AI can analyse, recommend and automate, while professional judgement and final audit decisions remain with the auditor.

Reviewable & Traceable Outputs

AI-generated analysis and recommendations remain reviewable by audit teams before they are relied upon or incorporated into engagement documentation.