Skip to content
New: ask the Rexfin Analyst Agent about your model. Every figure comes back cited.

Security & trust at Rexfin

Rexfin is built around a trust chain, not a promise: every figure moves from filed document to extracted value to reconciled total to citation to export, and every step is checkable. This page describes those controls plainly: what is live today, and what is still on the roadmap.

For a deeper technical walkthrough, a DPA, or our current compliance posture, talk to our team directly rather than a document.

Pursuing SOC 2 Type II, never claimed as certified until it is.

Animated loop: data flows through governed platform layers, policy gates allow or block each pass.

Where the controls live

Authentication and access Coming soon

Every workspace is scoped to one organization, and every seat inside it carries a role that determines which figures, models, and exports it can reach, not a shared login onto one big dataset.

Single sign-on and directory-based provisioning are next on our roadmap. We would rather say that plainly than claim it before it ships.

Role-based access control

Access to sensitive figures is scoped by role, and every organization’s model and data are logically isolated from every other organization’s.

A controller sees what a controller’s role reaches. A board pack built in one workspace has no path into another account through a shared table.

Audit and traceability

Every number in the platform keeps a trail back to the transaction or filed document it was built from, and material actions inside a workspace are logged.

Where a reviewer would normally ask “how do you know”, the answer here is a link to the source page, not a week spent reconstructing a spreadsheet.

Versioning and change control

Every close takes its own snapshot, so a live model keeps moving without disturbing the numbers a board pack was already built from.

Nothing leaves the platform as an export until the reconciliation checks between statements agree: an unverified number is refused at the door, never shipped with a caveat attached.

Data access rights

Metrics, segments, and adjustments are defined once in the definitions library and reused everywhere, so access rules apply consistently instead of drifting cell by cell the way a shared spreadsheet does.

Role-based scoping then determines who can see a given figure at all, independent of which report it surfaces in.

Data residency and sovereignty

GCC-first customers ask where their filings physically live before they ask almost anything else. We are architecting for in-region hosting aligned with SAMA and Saudi PDPL-style expectations.

That is a genuine, multi-month build we are directing engineering effort toward: a roadmap commitment, not a checked-off certification, and we will describe it as exactly that until it is true.

Continuity and recovery

Snapshots taken at every close mean a bad edit, a dropped connection, or an interrupted sync does not cost you your last reconciled state: you can get back to the version the numbers tied out against.

That snapshot recovery works today. Formal continuity and disaster-recovery planning, the playbook for larger-scale outages, is maturing alongside the rest of the security program as the team grows.

Secure rollout

New connections request the minimum scope a source will allow, read-only wherever the source supports it, with credentials held in an isolated secrets vault rather than inside the application database.

Our team walks every new workspace through its access design directly: talk to us before you connect anything.

Our security policies

Certifications and posture

We are pursuing SOC 2 Type II and will publish it the moment it is issued, not before. Until then, this page is the current, honest description of our controls.

The trust chain above (Filed → Extracted → Reconciled → Cited → Exported) is the actual mechanism behind that description, not a badge standing in for one.

Security ownership

At this stage, security decisions are not handed off to a separate department. The same people who design the reconciliation engine own access design, vendor review, and how an incident gets handled.

As the team grows, that ownership will formalize into named roles. It will not get vaguer in the meantime.

Encryption

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256.

Credentials for every connected source live in an isolated secrets vault, separate from the application data they unlock.

Internal access

The same per-organization isolation that keeps one customer’s data from another customer governs internal access too.

Nobody reaches a workspace’s figures by default: access is granted by role, not by working at Rexfin.

Monitoring and logging

Material actions inside a workspace (edits, exports, connection changes) are logged, feeding the same lineage and audit trail that makes any number’s history answerable on request.

AI security and governance

The Analyst and Modeler agents plan which figures to retrieve and what to compute, then answer from your model with assumptions and lineage attached, never asserting a number they cannot trace back to source.

Your data is never used to train shared models across customers, and instructions hidden inside an uploaded document are treated as untrusted input, not as commands to the agent.

Incident handling

If something goes wrong with a connection, an export, or a figure, we treat it as urgent and tell the affected workspace directly rather than waiting for a scheduled report.

We are not going to publish response-time numbers we have not earned yet.

Secure development

Changes to the modeling and reconciliation engine ship behind the same checks that gate a customer’s export: deterministic, reproducible, and reviewed before they reach a live workspace.

This page describes our security approach and direction, not a contractual commitment. For a security review, a DPA, or our current certification status, contact our team.

See it, don't just read about it

Bring one filed statement. We'll show you the whole trail.

No slide deck standing in for the product. In a live session we connect a sample of your stack, build the reconciled model, and let your team try to break the citation trail.

A R

Reconciled live