Security

How we protect your firm's data.

FinACEverse is built for regulated workloads. Identity, audit, and data handling controls are shared across every product on the platform.

Controls

What's in place today.

The list below covers what every customer gets out of the box. Firms with stricter requirements can layer additional controls on top.

Encryption in transit & at rest

TLS 1.2+ on every connection. Data encrypted at rest with provider-managed keys.

SSO & MFA

SAML / OIDC SSO available; MFA enforceable per firm. RBAC at firm, workspace, and resource level.

Audit logging

Every user action and every AI decision is logged with input, output, and reviewer — exportable.

Tenant isolation

Per-firm data isolation at the application layer; no cross-tenant queries possible by construction.

Least-privilege AI access

AI agents see only the data scoped to the current engagement; no firm-wide reads unless explicitly granted.

Hosting & residency

Hosted on enterprise cloud regions. Regional residency options available on the Firm plan.

Compliance

In progress.

Specific certifications and attestations are tracked privately and shared on request under NDA. For details, reach out via Contact.