Security & trust at Rexfin
Rexfin is built around a trust chain, not a promise: every figure moves from filed document to extracted value to reconciled total to citation to export, and every step is checkable. This page describes those controls plainly: what is live today, and what is still on the roadmap.
For a deeper technical walkthrough, a DPA, or our current compliance posture, talk to our team directly rather than a document.
Where the controls live
Authentication and access Coming soon
Every workspace is scoped to one organization, and every seat inside it carries a role that determines which figures, models, and exports it can reach, not a shared login onto one big dataset.
Single sign-on and directory-based provisioning are next on our roadmap. We would rather say that plainly than claim it before it ships.
Role-based access control
Access to sensitive figures is scoped by role, and every organization’s model and data are logically isolated from every other organization’s.
A controller sees what a controller’s role reaches. A board pack built in one workspace has no path into another account through a shared table.
Audit and traceability
Every number in the platform keeps a trail back to the transaction or filed document it was built from, and material actions inside a workspace are logged.
Where a reviewer would normally ask “how do you know”, the answer here is a link to the source page, not a week spent reconstructing a spreadsheet.
Versioning and change control
Every close takes its own snapshot, so a live model keeps moving without disturbing the numbers a board pack was already built from.
Nothing leaves the platform as an export until the reconciliation checks between statements agree: an unverified number is refused at the door, never shipped with a caveat attached.
Data access rights
Metrics, segments, and adjustments are defined once in the definitions library and reused everywhere, so access rules apply consistently instead of drifting cell by cell the way a shared spreadsheet does.
Role-based scoping then determines who can see a given figure at all, independent of which report it surfaces in.
Data residency and sovereignty
GCC-first customers ask where their filings physically live before they ask almost anything else. We are architecting for in-region hosting aligned with SAMA and Saudi PDPL-style expectations.
That is a genuine, multi-month build we are directing engineering effort toward: a roadmap commitment, not a checked-off certification, and we will describe it as exactly that until it is true.
Continuity and recovery
Snapshots taken at every close mean a bad edit, a dropped connection, or an interrupted sync does not cost you your last reconciled state: you can get back to the version the numbers tied out against.
That snapshot recovery works today. Formal continuity and disaster-recovery planning, the playbook for larger-scale outages, is maturing alongside the rest of the security program as the team grows.
Secure rollout
New connections request the minimum scope a source will allow, read-only wherever the source supports it, with credentials held in an isolated secrets vault rather than inside the application database.
Our team walks every new workspace through its access design directly: talk to us before you connect anything.
Our security policies
Certifications and posture
We are pursuing SOC 2 Type II and will publish it the moment it is issued, not before. Until then, this page is the current, honest description of our controls.
The trust chain above (Filed → Extracted → Reconciled → Cited → Exported) is the actual mechanism behind that description, not a badge standing in for one.
Security ownership
At this stage, security decisions are not handed off to a separate department. The same people who design the reconciliation engine own access design, vendor review, and how an incident gets handled.
As the team grows, that ownership will formalize into named roles. It will not get vaguer in the meantime.
Encryption
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256.
Credentials for every connected source live in an isolated secrets vault, separate from the application data they unlock.
Internal access
The same per-organization isolation that keeps one customer’s data from another customer governs internal access too.
Nobody reaches a workspace’s figures by default: access is granted by role, not by working at Rexfin.
Monitoring and logging
Material actions inside a workspace (edits, exports, connection changes) are logged, feeding the same lineage and audit trail that makes any number’s history answerable on request.
AI security and governance
The Analyst and Modeler agents plan which figures to retrieve and what to compute, then answer from your model with assumptions and lineage attached, never asserting a number they cannot trace back to source.
Your data is never used to train shared models across customers, and instructions hidden inside an uploaded document are treated as untrusted input, not as commands to the agent.
Incident handling
If something goes wrong with a connection, an export, or a figure, we treat it as urgent and tell the affected workspace directly rather than waiting for a scheduled report.
We are not going to publish response-time numbers we have not earned yet.
Secure development
Changes to the modeling and reconciliation engine ship behind the same checks that gate a customer’s export: deterministic, reproducible, and reviewed before they reach a live workspace.
This page describes our security approach and direction, not a contractual commitment. For a security review, a DPA, or our current certification status, contact our team.
See it, don't just read about it
Bring one filed statement. We'll show you the whole trail.
No slide deck standing in for the product. In a live session we connect a sample of your stack, build the reconciled model, and let your team try to break the citation trail.
Reconciled live