NeuFin is built for institutional-grade use. We apply bank-level security controls, maintain GDPR-conscious data handling practices, and are actively working toward SOC 2 Type II certification.
NeuFin's analyses and reports are decision-support tools for review by a licensed advisor — not investment advice, and not a substitute for professional financial, legal, or tax guidance.
✓AI inference: Anthropic API (US) · OpenAI API (US)
✓No personal data transferred outside EU/US without DPA coverage
Sub-processors
✓Anthropic — AI inference (Claude models)
✓OpenAI — AI inference (GPT-4o fallback)
✓Supabase — database and authentication
✓Railway — backend compute and hosting
✓Vercel — frontend hosting and edge CDN
✓Stripe — payment processing (PCI DSS Level 1)
Compliance
✓GDPR Article 28 — Data Processing Agreement available on request
✓SOC 2 Type II — audit in progress (target: Q3 2026)
✓Penetration test — scheduled annually; last test: internal review Q1 2026
✓Built to support MAS/MiFID-II-aligned advisory workflows
✓No data sold to third parties · No training on customer portfolio data
Application Security
✓OWASP Top 10 mitigations applied
✓CSP, HSTS, X-Frame-Options, and Referrer-Policy headers on all responses
✓Parameterized queries — no SQL injection surface
✓Rate limiting on all public endpoints
✓Admin endpoints protected by separate auth layer
Access Controls
✓Row-level security (RLS) in Supabase — users cannot access other users' data
✓Admin access requires explicit role grant + separate session validation
✓No shared credentials — every integration uses scoped service accounts
✓Audit log of admin actions (user plan changes, access grants)
Data Processing Agreement (DPA)
If your organization requires a signed DPA under GDPR Article 28, we provide a standard DPA covering all NeuFin sub-processors and data flows. Enterprise customers receive a countersigned copy within 2 business days.
We follow a 90-day coordinated disclosure policy. To report a security vulnerability, email security@neufin.ai with a description, steps to reproduce, and your contact details. We will acknowledge within 24 hours and provide a remediation timeline.