Security & Compliance
Security and compliance built for regulated advisors
Finterest is built compliance-first, so the controls a regulated advisory firm needs are built into the platform. This page explains what is in place today. Finterest supports your firm's compliance process. It does not replace your firm's supervision or approval.
Finterest encrypts sensitive credentials with AES-256 at rest and protects data in transit with TLS, isolates each user's data, and logs administrative actions. For compliance in outreach it supports pre-send message review, a server-side audit trail, recordkeeping, and call-recording disclosure controls that are off by default. Finterest supports your firm's compliance process; it does not replace your firm's supervision or approval.
How Finterest supports compliance in outreach
Pre-send message review
Communications can be reviewed before they go out, which supports the supervision the advisory rules expect.
Audit trail
Clickwrap terms acceptance is captured with a server-side audit trail.
Recordkeeping support
Outreach is recorded so messages can be retained and reviewed, supporting electronic-communication recordkeeping obligations.
Call-recording disclosure controls
Off by default, pending each firm’s legal review.
How Finterest protects data
AES-256 encrypted credentials
Sensitive credentials are encrypted at rest.
Encrypted in transit
Data is protected with TLS in transit.
Per-user data isolation
Each user’s data is isolated from others.
Admin audit log
Administrative actions are logged.
For exactly what we collect, how we use it, and how it is stored and shared, see our Privacy Policy.
Microsoft Verified Publisher
Microsoft has verified Finterest's publisher identity for our Microsoft 365 and Sign-in-with-Microsoft integrations, so the apps you connect are confirmed as genuinely ours. Publisher verification confirms the authenticity of the app's publisher and is not a security assessment or endorsement by Microsoft.
A note on compliance language
Finterest is a software platform that supports your firm's compliance program. It is not a compliance authority, and using Finterest does not by itself satisfy FINRA, SEC, or firm-specific obligations. Your firm's principals and compliance team remain responsible for supervision, approval, and recordkeeping. For the rules themselves in plain language, see the compliance guide.
Frequently asked questions
How does Finterest protect advisor and client data?
Sensitive credentials are encrypted with AES-256 at rest, data is protected with TLS in transit, each user's data is isolated from others, and administrative actions are logged.
Does Finterest support pre-send compliance review?
Yes. Communications can be reviewed before they go out, which supports the supervision the advisory rules expect. Clickwrap terms acceptance is captured with a server-side audit trail.
Does Finterest keep records of outreach?
Yes. Outreach is recorded so messages can be retained and reviewed, supporting electronic-communication recordkeeping obligations.
Does Finterest record calls?
Call-recording disclosure controls are off by default, pending each firm's legal review.
Is Finterest a Microsoft Verified Publisher?
Yes. Microsoft has verified Finterest's publisher identity for its Microsoft 365 and Sign-in-with-Microsoft integrations. Publisher verification confirms the authenticity of the app's publisher and is not a security assessment or endorsement by Microsoft.