F
Finki

Security

Last reviewed: September 2026

Finki holds portfolio data for retail investors and for wealth managers acting on behalf of their clients. This page describes how that data is isolated, who can reach it, and where it lives. Every statement below was verified in an internal audit of the running system. Where a control does not yet exist, we say so.

For security questionnaires or vendor reviews, contact us at contact@tryfinki.com.

At a glance

Tenant isolation
PostgreSQL Row-Level Security on every customer table
Authorisation
Three independent layers: edge, page, database
Broker access
Read-only via SnapTrade. No order placement.
Data residency
EU, for database and authentication
Transport
TLS 1.2/1.3, forward secrecy, HSTS (platform-managed)
At rest
AES-256 encryption (platform-managed)
Code scanning
Static analysis, secrets, dependencies, custom rules

Isolation enforced by the database

Every table holding customer data has PostgreSQL Row-Level Security (RLS) enabled, with owner-scoped policies on all four operations: select, insert, update and delete. RLS policies are evaluated by the database engine itself, not by application code, so a bug in the application layer does not bypass the policy check. This is defence in depth: the database enforces isolation independently of the code paths above it.

Three independent authorisation layers

A request passes three checks that do not depend on each other:

  • Edge middleware verifies the session before the request reaches the application
  • A server-side page gate verifies it again before rendering
  • Row-Level Security in the database scopes every query to the authenticated owner

A failure in any one layer does not expose data. This was demonstrated during our audit, not assumed.

Authentication on every endpoint

Every API endpoint serving customer data requires an authenticated session and verifies it before touching data. Machine-to-machine endpoints use cryptographic signatures (HMAC-SHA256), compared in constant time.

The requester's identity is never taken from the request body. It is always derived from the verified session. This eliminates the most common multi-tenant vulnerability class by design: there is no user identifier a caller can supply to reach someone else's data.

Broker connections

Broker connections are read-only, established through SnapTrade. Finki reads accounts, positions, balances and transaction history. It can never place a trade or move money.

Broker connection credentials are stored with deny-by-default access: unreachable from the browser under any query, reachable only by the backend service.

Calculation backend

Our calculation backend reads only market data: prices and exchange rates. It has no access to customer holdings, so the compute layer cannot expose a portfolio.

Encryption in transit

Connections use TLS 1.2 or 1.3 only, with forward-secrecy cipher suites and HSTS. TLS termination is provided by our hosting platform (Vercel); cipher suite selection and post-quantum key exchange support depend on the platform's configuration and the client browser.

Data residency

The database and authentication service are hosted in the EU. The full list of processors is in our privacy policy.

Automated scanning on every change

Every code change runs through:

  • Static analysis
  • Secret scanning
  • Dependency vulnerability scanning
  • Custom rules that block code which could bypass our isolation guarantees

Encryption at rest

Data at rest is encrypted by the managed database platform (Supabase/PostgreSQL on AWS) using AES-256. This is a platform-level property; Finki does not manage encryption keys directly.

Backup and recovery

Database backups are handled by the managed platform (Supabase). Specific retention policies and recovery objectives are available on request.

Incident response

To report a security vulnerability, contact us at contact@tryfinki.com. All reports are investigated.

What we don't claim yet

Two things a security review will ask about, stated plainly:

  • We are not yet SOC 2 or ISO 27001 certified.
  • We have not yet commissioned a third-party penetration test.

Both are on the roadmap. We will publish them here when they are true, and not before.

Not financial advice

All output from Finki is for educational and informational purposes only. Finki does not hold a MiFID II investment advisory licence. Nothing on this platform constitutes a personalised investment recommendation. See our terms of service.

Contact

To report a vulnerability or request further detail for a security review, contact us at contact@tryfinki.com.

Automated security contact details are published in security.txt.