Security & trust
Financial data deserves more than a privacy promise.
Trust is the product. Here is concretely how Rexfin keeps your financial data isolated, encrypted, and under your control.
Pursuing SOC 2 Type II. Ask for our current posture →
- Encrypted end to end
- Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Credentials for connected systems are stored in an isolated secrets vault.
- Never trains shared models
- Your financial data is never used to train shared or third-party models. It is used only to serve answers within your own organization.
- Per-organization isolation
- Each organization’s model and data are logically isolated. Access is scoped by role, so sensitive figures stay with the people who should see them.
- Auditable by design
- Every figure carries lineage back to source transactions, and material actions are logged — built for diligence, audit, and internal controls.
- Least-privilege access
- Connections request the minimum scopes needed to read financial data. Read-only wherever the source supports it.
- Your data, your call
- Disconnect a source or delete your data at any time. We honor deletion requests and keep retention transparent.
This page describes our security approach and direction, not a contractual commitment. For your security review, DPA, and current certifications, contact our team.
Book a demo
Run your security review with us.
Book a demo or reach out and we'll walk your team through data handling, access controls, and deployment.