Security & Compliance

Security and compliance built for regulated advisors

Finterest is built compliance-first, so the controls a regulated advisory firm needs are built into the platform. This page explains what is in place today. Finterest supports your firm's compliance process. It does not replace your firm's supervision or approval.

Finterest encrypts sensitive credentials with AES-256 at rest and protects data in transit with TLS, isolates each user's data, and logs administrative actions. For compliance in outreach it supports pre-send message review, a server-side audit trail, recordkeeping, and call-recording disclosure controls that are off by default. Finterest supports your firm's compliance process; it does not replace your firm's supervision or approval.

How Finterest supports compliance in outreach

  • Pre-send message review

    Communications can be reviewed before they go out, which supports the supervision the advisory rules expect.

  • Audit trail

    Clickwrap terms acceptance is captured with a server-side audit trail.

  • Recordkeeping support

    Outreach is recorded so messages can be retained and reviewed, supporting electronic-communication recordkeeping obligations.

  • Call-recording disclosure controls

    Off by default, pending each firm’s legal review.

How Finterest protects data

  • AES-256 encrypted credentials

    Sensitive credentials are encrypted at rest.

  • Encrypted in transit

    Data is protected with TLS in transit.

  • Per-user data isolation

    Each user’s data is isolated from others.

  • Admin audit log

    Administrative actions are logged.

For exactly what we collect, how we use it, and how it is stored and shared, see our Privacy Policy.

Microsoft Verified Publisher

Microsoft has verified Finterest's publisher identity for our Microsoft 365 and Sign-in-with-Microsoft integrations, so the apps you connect are confirmed as genuinely ours. Publisher verification confirms the authenticity of the app's publisher and is not a security assessment or endorsement by Microsoft.

A note on compliance language

Finterest is a software platform that supports your firm's compliance program. It is not a compliance authority, and using Finterest does not by itself satisfy FINRA, SEC, or firm-specific obligations. Your firm's principals and compliance team remain responsible for supervision, approval, and recordkeeping. For the rules themselves in plain language, see the compliance guide.

Frequently asked questions

How does Finterest protect advisor and client data?

Sensitive credentials are encrypted with AES-256 at rest, data is protected with TLS in transit, each user's data is isolated from others, and administrative actions are logged.

Does Finterest support pre-send compliance review?

Yes. Communications can be reviewed before they go out, which supports the supervision the advisory rules expect. Clickwrap terms acceptance is captured with a server-side audit trail.

Does Finterest keep records of outreach?

Yes. Outreach is recorded so messages can be retained and reviewed, supporting electronic-communication recordkeeping obligations.

Does Finterest record calls?

Call-recording disclosure controls are off by default, pending each firm's legal review.

Is Finterest a Microsoft Verified Publisher?

Yes. Microsoft has verified Finterest's publisher identity for its Microsoft 365 and Sign-in-with-Microsoft integrations. Publisher verification confirms the authenticity of the app's publisher and is not a security assessment or endorsement by Microsoft.

Bring this to your compliance team