Our Security Commitment
At Finthy, security isn’t an afterthought—it’s the foundation of everything we do. We understand that you’re trusting us with your most sensitive financial information, and we take that responsibility seriously.
Bank-Level Security Standards
End-to-End Encryption
- AES-256 encryption for all data at rest
- TLS 1.3 for all data in transit
- Zero-knowledge architecture - we can’t see your banking credentials
- Encrypted API communications with all financial institution partners
Secure Banking Connections
- No credential storage - your banking passwords are never saved
- Read-only access to account information
- OAuth 2.0 and Open Banking standards where available
- Multi-factor authentication support for enhanced protection
Regional Security Compliance
United States
- SOC 2 Type II certified data providers (Plaid, Open Finance)
- Plaid integration with bank-grade API security and tokenized access
- Data handling aligned with GLBA (Gramm-Leach-Bliley Act)
- PCI DSS Level 1 payment processing via Stripe
- Automatic sync with 11,000+ US financial institutions
Canada
- Aligned with PIPEDA (Personal Information Protection and Electronic Documents Act)
- OSFI (Office of the Superintendent of Financial Institutions) guidelines adherence
- Plaid integration with secure, tokenized connections to 300+ Canadian banks
- SOC 2 Type II certified data providers (Plaid, Open Finance)
Mexico
- Aligned with CNBV (National Banking and Securities Commission) requirements
- Secure Chrome Extension with isolated data processing
- PCI DSS Level 1 payment processing via Stripe
- SOC 2 Type II certified data providers (Plaid, Open Finance)
Chile
- CMF (Financial Market Commission) regulatory alignment
- Open Finance API integration with certified security protocols
- Local data residency options for Chilean customers
- Hosted in ISO 27001-certified data centers
Brazil
- Built on the Banco Central do Brasil Open Banking framework
- Aligned with LGPD (Lei Geral de Proteção de Dados)
- Open Finance security framework with bank-grade protection
- Regular penetration testing and security audits
Data Protection Principles
Privacy by Design
- Minimal data collection - we only gather what’s necessary
- Purpose limitation - data used only for stated purposes
- Data minimization - automatic deletion of unnecessary information
- User control - you own your data and can delete it anytime
Access Controls
- Role-based permissions for internal team access
- Multi-factor authentication for all administrative functions
- Regular access reviews and principle of least privilege
- Audit logs for all data access and modifications
Infrastructure Security
Cloud Security
- AWS/Google Cloud enterprise-grade infrastructure
- Geographic data replication for disaster recovery
- Automated security monitoring and threat detection
- Regular security updates and vulnerability patching
Application Security
- Secure development lifecycle (SDLC) practices
- Regular security code reviews and static analysis
- Dynamic application security testing (DAST)
- Bug bounty program for continuous security improvement
Third-Party Integrations
Financial Data Providers
- Plaid (USA & Canada) - SOC 2 Type II certified, tokenized bank connections
- Open Finance (Brazil) - SOC 2 Type II certified
- Open Finance (Chile) - Bank-certified Open Banking provider
- Chrome Extension (Mexico) - Isolated, user-controlled bank data sync
- Regular security assessments of all partners
Certifications Across Our Stack
Finthy doesn’t hold these certifications directly; we’re built on infrastructure and partners that do:
- ISO 27001: our cloud infrastructure (AWS / Google Cloud)
- SOC 2 Type II: our bank-data providers (Plaid, Open Finance)
- PCI DSS Level 1: our payment processor (Stripe)
Incident Response
24/7 Monitoring
- Real-time threat detection and automated responses
- Security Operations Center (SOC) monitoring
- Incident response team with defined escalation procedures
- Customer notification protocols for any security events
Transparency
- Regular security updates to our community
- Clear communication during any security incidents
- Post-incident reports with lessons learned and improvements
- Open security practices documentation
Your Security Responsibilities
Account Protection
- Use strong, unique passwords for your Finthy account
- Enable two-factor authentication when available
- Keep your devices updated with the latest security patches
- Log out from shared or public devices
Stay Informed
- Review account activity regularly in the dashboard
- Report suspicious activity immediately to our support team
- Keep your contact information updated for security notifications
- Follow our security blog for the latest protection tips
Security Resources
For Users
For Developers
- API Security Documentation - Secure integration guidelines
- Webhook Security - Proper signature verification methods
- Rate Limiting - API usage limits and best practices
Contact Our Security Team
If you have security concerns or want to report a vulnerability:
- Security Email: [email protected]
- Bug Bounty: Report vulnerabilities responsibly
- General Support: Contact our team for account-related security questions
Last updated: February 3, 2026
We continuously update our security measures to stay ahead of emerging threats. This page reflects our current security practices and will be updated as we enhance our protection measures.