Security at FinMark.ai
We handle vendor invoices and post to your general ledger. Here is exactly what we do with your data, what we never touch, and how to review us properly.
Blast radius
The safest permission is the one we never ask for
FinMark.ai stops at the ERP. Invoices are captured, matched, tax-computed, sanity-checked and approved, then posted back into your ERP audit-ready — and that is where our involvement ends. We do not execute payments. Payment stays with your bank, your treasury, and the controls your finance and compliance teams already trust.
That is a deliberate design decision, not a missing feature. A system that cannot move money cannot be used to move money, which takes the single largest category of financial risk off the table before any other control is considered.
The same principle runs through the rest of the platform. Where SharePoint is already your document repository, invoices stay there — picked up from your existing folders, with your existing access controls, retention policies and audit logs still governing them. Nothing has to be migrated into a new storage layer to be processed.
Data protection
Encrypted in transit and at rest, isolated by tenant
Customer data is hosted on enterprise-grade cloud infrastructure with encryption in transit and at rest, and regional data residency where required by the customer or by regulation.
Every subsidiary runs as its own isolated tenant. Group structures are the norm in the enterprises we serve — a parent holding company with several operating subsidiaries, each with its own ERP instance, vendor base, approval policy and tax obligations — and the isolation between them is enforced by the platform, not by convention.
A separate admin view runs above the tenants. Super admins, typically group CFOs and internal audit, can see invoices, approvals and key metrics across every subsidiary in one place without that isolation being weakened for anyone else.
Access and accountability
Least privilege, and a trail for every decision
Access follows least privilege: people and services get the minimum needed to do their job, and no more.
Actions are logged. Because tax and matching decisions are made automatically, the rule that produced each one stays visible in the audit trail — an auditor asking why a particular withholding tax rate was applied to a particular invoice can be shown the answer rather than told it.
Assurance
Tested regularly, and documented for your review
The platform is subject to regular penetration testing, and operates on infrastructure and controls aligned with enterprise-grade security standards.
FinMark.ai is not currently SOC 2 or ISO 27001 certified. We would rather say that plainly than imply otherwise and have it surface halfway through your review. If your process requires a certified vendor, tell us early and we will be straight with you about where we are.
A full security questionnaire is available on request, and we are happy to complete your own. Ask your point of contact, or use the form below.
Security questions, answered
Reviewing us? Start here.
Ask for the security questionnaire, or send us yours and we'll complete it.