Trust
Trust Center
Finn runs regulated voice conversations at scale — healthcare, finance, insurance — on a certified information security management system (ISO/IEC 27001:2022), with service management and quality systems certified alongside and a SOC 2 Type II audit underway with A-LIGN.
Last updated: June 18, 2026
Reliability
System status
All systems operational
Monitored externally since 18 Jul 2026 · updated live
100%
Uptime · last 46 days
Security & data protection
Compliance is the floor, not the ceiling.
Voice is regulated. Healthcare, finance, insurance, legal — Finn was built to run there from day one.
A certified information security management system
Rather than ask you to take our word for it, we point at the audit. Our ISMS is certified to ISO/IEC 27001:2022 for the scope above — the standard whose Annex A controls cover access control, cryptography, operations security, logging and monitoring, supplier relationships, and incident management. Certification was assessed by an independent, EUAS-accredited body and is maintained through annual surveillance audits.
Customers under NDA can request our Statement of Applicability and control detail through their account team.
Data residency
Your workspace's storage region is selected at provisioning — Iowa, Mumbai, Singapore, Sydney, London, or Frankfurt — and call recordings and transcripts come to rest there. Regional separation falls within the scope of our ISO/IEC 27001 certification.
For the region assigned to your workspace, or a written residency attestation for a vendor review, contact [email protected].
Model inference and speech services run on additional providers — see Subprocessors for the full list and per-workspace-region processing views.
Encryption in transit and at rest
AES-256 at rest, TLS 1.2/1.3 in transit. Recordings, transcripts, PII — all encrypted by default.
Tenant isolation
Every workspace's data is logically segregated — one customer can never query, call, or access another's data or voice instances.
PII redaction
Per-deployment redaction toggle for transcripts — defense in depth alongside our DPA's instruction not to collect card numbers or government IDs on calls.
Access control
Granular permissions per user, per workspace. Production access restricted to authorized personnel via MFA and SSH keys, on least privilege.
Certifications & audits
Certifications
SOC 2 Type II — A-LIGN
Audit in progressOur observation window is underway with A-LIGN, an independent audit firm, with the report expected August 2026. We are not SOC 2 attested today and the report is not yet available for distribution — when A-LIGN completes the audit we will publish it here.
ISO certificates held
ISO/IEC 27001:2022
Information Security Management
- Certificate
- UKBIZ/25D/ISMS/0062
- Issued
- 19 May 2025
- Valid through
- 18 May 2028
ISO/IEC 20000-1:2018
IT Service Management
- Certificate
- UKBIZ/25G/ITMS/0061
- Issued
- 19 May 2025
- Valid through
- 18 May 2028
ISO 9001:2015
Quality Management
- Certificate
- UKBIZ/25K/QMS/0060
- Issued
- 19 May 2025
- Valid through
- 18 May 2028
HIPAA Business Associate Agreement
For enterprise customers processing PHI. Executed per engagement.
Request via emailStandard Contractual Clauses
Executed copy with completed annexes for EU, UK, and Swiss transfers.
Request via emailISO 27001 Statement of Applicability
Annex A control detail, shared under NDA.
Request via emailCertified scope. Real-time AI voice agents that handle outbound and inbound calls, automating conversations, bookings, and support with natural, human-like speech and system integrations.
Beyond the certifications
Regulatory posture
The platform is built and operated around the regimes below. These are obligations we design for — distinct from the independently audited certifications above.
GDPR / ePrivacy
European Union & EEA
DPDP Act 2023
India
HIPAA
United States — BAAs available for PHI workloads
TRAI & RBI
India — telecom and financial communication
TCPA / FTC TSR
United States — telemarketing
Responsibility for consent, call intent, and audience sourcing sits with the customer. Our Consent & Legal Guidance sets out what that means in each region.
Policies & agreements
Documentation
Privacy Policy
What we collect, why, and how it's used.
Data Processing Addendum
Our contractual data-protection commitments.
Subprocessors
The third parties that process data on our behalf, with per-region processing locations.
Data-flow map
How call and audience data moves through our subprocessors.
Security & trust
Encryption, access control, residency, and audit posture.
AI data use & retention
No training on your data, zero-retention model APIs where offered on eligible plans, and deletion timelines.
Vulnerability Disclosure Policy
How to report a security issue — scope, safe harbor, and our response.
Consent & Legal Guidance
Regulatory obligations and consent requirements for voice campaigns.
Terms of Service
The agreement governing use of Finn.
Refund & Cancellation Policy
Eligibility, request process, and timelines.
System status
Live uptime and incident history.
Get in touch
Security contact
Report a security concern
If you believe you've found a vulnerability, email [email protected] with steps to reproduce, affected endpoints, and any supporting detail. We investigate every report and respond directly. We ask that you allow up to 90 days from your report before any public disclosure — we’ll coordinate timing with you.
Security review or vendor onboarding
For security questionnaires, DPAs, company registration details, or documentation not published here, contact [email protected].
AIforge Tech Private Limited · CIN U62099RJ2025PTC099494 · Jaipur, Rajasthan, India
Empieza ahora
Contrata a Finn y escala con confianza.
Pasa de la idea a la automatización de voz en vivo: de forma segura, fiable y sin riesgo operativo.
Lanzamientos quincenales
Avanzamos rápido y te damos lo que necesitas
Herramientas potentes
Paneles, informes, automatizaciones y más, ya listos