Trust center

Finaxis Trust Center

Finaxis security controls, compliance, connections and documents.

Updated October 7, 2026

Data
Hosted in Canada
AI infrastructure
In Canada
Security assessment
CASA Tier 2, verified
Encryption
In transit and at rest

Non-technical version: security at a glance.

Compliance

CASA Tier 2

Verified

Finaxis is CASA Tier 2 verified by the App Defense Alliance. Assessment carried out by an authorized lab against the OWASP ASVS standard.

Letter of validation on request

Quebec's Law 25

Supported

Quebec's private-sector privacy law. Finaxis supports its customers' compliance with this law.

No certification exists for this law.

PIPEDA

Supported

Canada's federal private-sector privacy law. Finaxis supports its customers' compliance with this law.

No certification exists for this law.

Infrastructure

Data centres

Data hosted in Canada. Certifications held by the hosting provider:

  • ISO/IEC 27001
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701

AI infrastructure

AI models deployed in a private environment, on infrastructure in Canada, unless stated otherwise. Certifications held by the provider:

  • ISO/IEC 27001
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • SOC 1 Type 2
  • SOC 2 Type 2
  • SOC 3
  • CSA STAR

These certifications belong to our providers and cover their infrastructure, not Finaxis. Provider names on request.

Documents

Policies are public; other documents on request.

  • Privacy policy

    Personal information, retention and rights.

    Public Open
  • Terms of use

    Terms for using the platform.

    Public Open
  • Vulnerability disclosure policy

    Scope, testing rules and reporting address.

    Public Open
  • CASA Tier 2 letter of validation

    Issued at the end of the assessment.

    On request Request
  • Hosting and AI providers

    Names and certification attestations.

    On request Request
  • List of subprocessors

    Providers, their function and the data they process.

    On request Request
  • Security questionnaire

    Your organization's questionnaire, completed by Finaxis.

    On request Request

Security controls

30 controls, by area.

Data and hosting

4
  • Hosted in Canada

    Customer data hosted in Canada.

  • Encryption

    Data encrypted in transit and at rest.

  • Customer separation

    Every record belongs to one customer account. Access is checked on every request.

  • No resale

    Data never sold or used for advertising.

Identity and sign-in

6
  • Single sign-on

    Google and Microsoft.

  • Passkeys

    Passwordless sign-in (WebAuthn).

  • Two-factor authentication

    Authenticator app, SMS or recovery codes.

  • Required 2FA

    An administrator can require it for the whole account.

  • Passwords

    Hashed, never stored in plain text.

  • Sign-in alerts

    Email on every sign-in from a new device. Attempts are rate-limited.

Permissions and audit trail

5
  • Roles

    Administrator, editor, viewer and guest. The Nova plan lets you create and manage more granular access roles than the Billie plan.

  • Permissions by data type

    Separate rights for invoices, customers, users, mailboxes and the other data types.

  • Customer assignment

    A user limited to the customers assigned to them.

  • Server-side enforcement

    Permissions checked by the API, not just in the interface.

  • Activity log

    Who did what, when and from where. Administrators only.

Application security

5
  • CASA Tier 2

    Application tested by an authorized lab against the OWASP ASVS standard.

  • Static code analysis

    On every code change.

  • Dependency scanning

    Against known-vulnerability databases.

  • Weekly security review

    Scan results reviewed every week.

  • Error monitoring

    Continuous, with personal information scrubbed.

Integrations and email

4
  • OAuth 2.0

    QuickBooks, HubSpot, Google and Microsoft. Finaxis never receives your passwords.

  • Revocable at any time

    In Finaxis, or in QuickBooks, HubSpot, Google or Microsoft.

  • Acomba agent

    Transmission over HTTPS.

  • Authenticated sending domain

    Reminders sent from your domain, connected to our sending servers through MX, DKIM and DMARC.

Artificial intelligence

4
  • Private environment in Canada

    Models deployed in a private environment, on infrastructure in Canada, unless stated otherwise.

  • No shared training

    Your data trains no AI model shared across customers.

  • Values replaced

    Where possible, amounts, due dates and the contact's first name replaced with placeholders in what the AI writes. Real values filled in afterwards by Finaxis.

  • Certified provider

    Provider certifications listed under Compliance.

Transparency

2
  • Public status page

    status.finaxis.ai

  • Vulnerability disclosure

    Public policy and security.txt file.

Connections and permissions

Permissions Finaxis requests for each connection.

System Connection Used by Finaxis for Permissions requested
QuickBooks Online OAuth 2.0 Invoices, customers and payments.
  • com.intuit.quickbooks.accounting
  • openid
Acomba Windows agent on your machine, transmission over HTTPS Invoices, customers and payments. No OAuth permissions
HubSpot OAuth 2.0 Reading the CRM. Adding the reminders Finaxis sends to the CRM.
  • oauth
  • crm.objects.companies.read
  • crm.objects.companies.write
  • crm.objects.contacts.read
  • crm.objects.contacts.write
  • crm.objects.deals.read
  • crm.objects.owners.read
  • crm.schemas.companies.read
  • crm.schemas.contacts.read
  • crm.schemas.deals.read
  • sales-email-read
  • files
Google Workspace (Gmail) OAuth 2.0 Sending reminders from your mailbox. Reading replies, if turned on.
  • gmail.send
  • userinfo.email
  • gmail.readonly*
Microsoft 365 (Outlook) OAuth 2.0 Sending reminders from your mailbox. Reading replies, if turned on.
  • Mail.Send
  • User.Read
  • offline_access
  • Mail.ReadWrite*
Other mailbox IMAP and SMTP Sending reminders and reading replies. No OAuth permissions
CSV file Manual import No standing connection. No OAuth permissions

* Only if Finaxis reads replies

Subprocessors

Functions handled by providers. Named list, with the data processed, on request.

Request the list
  • Hosting and storage

    Servers and storage for the platform.

  • AI models

    Writing and analysis by the agents.

  • Web search

    Public information about your business customers, for the AI.

  • Email delivery

    Reminders sent from a Finaxis address or your domain.

  • SMS delivery

    SMS reminders and sign-in codes.

  • Error monitoring

    Error detection, with personal information scrubbed.

  • Support

    Tracking requests sent to our team.

Technical questions

Yes. Every record belongs to one customer account, and the API checks the user's membership and role on every request. One customer's data is never accessible to another.

AI models run in a private environment. Your data trains neither those models nor any model shared across customers. Billie answers only with the data the user's role and assigned customers allow. Where possible, amounts, due dates and the contact's first name are replaced with placeholders in what the AI writes; Finaxis then fills in the real values.

In a private environment, on infrastructure in Canada, unless stated otherwise. The provider's name is sent on request.

Your data trains no AI model shared across customers.

Yes. An administrator can require it for the whole account. With Google or Microsoft sign-in, the second factor is the identity provider's.

Yes, by role (administrator, editor, viewer or guest) and by customer assignment.

The user chooses among three options. By default, from a Finaxis address specific to your company. From your own mailbox, or one a colleague has shared with you, on Google Workspace, Microsoft 365 or an IMAP server. Or from your own domain, connected to our sending servers through MX, DKIM and DMARC DNS records.

Disconnect the integration in Finaxis, or remove access in QuickBooks, HubSpot, Google or Microsoft. For Acomba, uninstall the agent.

Yes. Attach yours to your security file request.

Report a vulnerability

Scope, testing rules, reporting address and Finaxis's commitments.

https://finaxis.ai/.well-known/security.txt

Read the policy

Security file

CASA Tier 2 letter of validation, providers, subprocessors and security questionnaire.

Request the security file