Security
Your numbers under your control.
Finance data is the most sensitive data a company has. Here is how finstory keeps it safe, who can see it, and what the AI is and isn't allowed to do.
Where your data lives
finstory runs on Google Cloud in the United States. Data from the EU or UK is transferred under the EU Standard Contractual Clauses.
Encrypted everywhere
Data is encrypted in transit and at rest, and the credentials that connect finstory to your ERP are stored encrypted too.
Sign-in you already trust
Sign in with Google or Microsoft, so your own identity policies apply, or with email. Access to our production systems is restricted and monitored.
Roles and permissions
Readers view, editors build and publish stories, power users manage reports and data, and only admins can grant admin rights or load data through Claude.
Publishing you control
Keep a story private, share it with your company, send it to named people, or create a link that expires. Revoke access at any time.
Every change on record
Every edit to a story or report, by a person or by the AI, is kept in version history and can be restored.
Clear limits for the AI
The assistants run in your own Claude and only see what they fetch for your request, from the workspace you signed in to. Only admins can load data, and only after a dry run with a rollback copy saved.
Your data stays yours
You own your data and everything derived from it. We never use it for marketing, demos or anything outside your account.
Leaving finstory
If you end your subscription, we keep your data for up to 30 days so you can export it, then delete it. Backups that contain it are purged within 60 days, unless the law requires otherwise.
Security review
Need the details for your review?
Request our SOC 2 report and security overview. We usually reply within one business day.