Trust
How we handle your financial data.
This page is maintained by Finendra to answer common security and privacy questions about how we work. It describes our current practices — it is not a certification or an independent audit.
Access control
Team members receive least-privilege access to your accounting systems, limited to the people assigned to your engagement. Access is reviewed when roles change and revoked when an engagement ends.
Authentication on our systems
Administrative areas of this site require an authenticated account, sign-in and password-reset attempts are rate-limited with lockouts, and passwords are checked against known-breach databases.
Data in transit
This website and the systems we use to receive documents are served over TLS. We ask clients to send financial records through encrypted channels rather than plain email attachments.
Data separation
Records submitted through this site are stored with row-level access rules so that a given record is reachable only by authorised Finendra personnel — not by other visitors or clients.
Confidentiality
Every Finendra team member is bound by a confidentiality agreement covering client financial information, and client data is used only to deliver the engaged scope.
Shared client quotes
Quote links shared with clients use long random tokens, expire automatically, and can be revoked at any time. A link exposes only the single quote it was issued for.
Finendra is responsible for
- Limiting internal access to your data to the assigned engagement team
- Keeping our own accounts protected and reviewing access regularly
- Handling your records only for the agreed scope of work
- Telling you promptly if we become aware of an issue affecting your data
You are responsible for
- Granting us the minimum access your engagement requires
- Managing users and permissions inside your own accounting and payroll platforms
- Removing our access when an engagement ends, alongside our own revocation
- Following your own internal approval controls for payments and payroll
Reporting a security concern
If you believe you have found a vulnerability in this site, or you have a question about how your data is handled, email hello@finendra.com with the details. Please give us a reasonable window to investigate before disclosing anything publicly.
For how we collect and retain information, see our Privacy Policy.
Have a security questionnaire to complete?
Send it over and we will work through it with you as part of the discovery process.