Inside the Rexfin Trust Center: What We Can Prove Today, and What We Can't Yet
Rexfin's trust center states the real security controls we have, names the gaps in plain English, and never claims a certification we can't back.
By The Rexfin team
A bank-adjacent finance team evaluating a vendor for anything touching real financial statements does not start with a product demo. It starts with a security or legal committee asking for proof, and for a vendor asking a CFO to route sensitive filings through an AI pipeline, those questions run sharper than average. Rexfin’s trust center exists to answer them before they’re asked in a live negotiation, because “let me get back to you” is where a deal quietly stalls.
Say the real control, name the real gap, in the same sentence
We score our own security controls against the full ISO 27001:2022 Annex A checklist internally. Publicly, we follow one rule for every claim on the trust page: state the real, operating part of a control as true, and name the specific gap in plain English, in the same sentence. Never a bare status label, never silence about what’s missing.
In practice that looks like: passwords are hashed with a modern, memory-hard algorithm and never stored in plaintext; we have not yet added multi-factor authentication, and it’s on our near-term roadmap. Or: nightly backups run and full restores have been tested successfully; those backups don’t yet live on separate infrastructure from the primary database, so our recovery point today is measured in hours, not seconds. An overclaim on this page would be worse for us than shipping late, because the first skeptical reviewer who catches daylight between our claims and reality does lasting damage to the one thing our product is supposed to guarantee.
The same discipline covers our AI subprocessor. We use a third-party AI model to help extract data from documents, and until the data processing agreement covering that relationship is fully executed and disclosed, we don’t publish it on a public subprocessors list as though the relationship were already formalized: that would itself be a false claim, worse than the current placeholder. Until then, a serious buyer gets the real, current picture directly under NDA. Read more about how we govern that relationship in LLM provider governance.
ISO 27001, not SOC2: and why
For GCC and government-adjacent buyers, ISO 27001 is the more recognized signal; SOC2 matters mostly to US-influenced buyers and isn’t our default target. Today, our information security management system (policies, a full control assessment, a live risk register) is complete, but formal third-party certification has not started. We say exactly that: a complete ISMS aligned to ISO 27001:2022, with certification planned once we have an engagement that requires it. We do not say “certification in progress,” because that implies an audit is already booked, and none is. The phrasing everywhere on the page is “designed to ISO-aligned controls,” never a claim of a certificate we don’t hold.
Ready answers instead of awkward silence
A few questions come up in nearly every serious procurement conversation before the underlying artifact fully exists: do you have an independent penetration test report, are you insured, can you share client references. Our answer to each is specific rather than evasive. On the pentest: name the vendor, name the booked date, point to our own continuous automated security testing running clean meanwhile. On insurance: coverage is a hard gate we hold ourselves to before signing any contract, we won’t sign before a binder is bound, and we’ll share the certificate the moment it is. On references: we say plainly that we’re early-stage and don’t have a long customer list yet, rather than dodge it.
We also maintain a pre-filled security questionnaire (the format most GCC buyers accept before demanding a formal certificate) built directly from our real control assessment. For the mechanics behind how a cited number gets checked before it reaches an answer, see how verification works.
What happens if we disappear
Any small vendor sitting between your ledger and board pack should expect this question. The honest position today: continuity planning that lets a designated second person step in during an emergency is a commitment we’re actively building toward, not yet a fully staffed reality: we say that plainly rather than imply more coverage than exists. What we already commit to regardless: your data stays exportable in a usable format no matter what happens to us. See data retention and deletion and security architecture overview.
Why this matters more than a badge
A trust center full of logos and certification badges is easy to produce. One that tells you precisely what’s real, what’s partial, and what’s still on the roadmap is harder to write and slower to build, but it’s the only version a skeptical GC team can actually rely on: the same standard we hold the rest of the Rexfin platform to.
Part of Inside the Rexfin Platform: How the Trust Machinery Works