CASA Tier 2
VerifiedFinaxis is CASA Tier 2 verified by the App Defense Alliance. Assessment carried out by an authorized lab against the OWASP ASVS standard.
Letter of validation on request
Trust center
Finaxis security controls, compliance, connections and documents.
Updated October 7, 2026
Non-technical version: security at a glance.
Finaxis is CASA Tier 2 verified by the App Defense Alliance. Assessment carried out by an authorized lab against the OWASP ASVS standard.
Letter of validation on request
Quebec's private-sector privacy law. Finaxis supports its customers' compliance with this law.
No certification exists for this law.
Canada's federal private-sector privacy law. Finaxis supports its customers' compliance with this law.
No certification exists for this law.
Data hosted in Canada. Certifications held by the hosting provider:
AI models deployed in a private environment, on infrastructure in Canada, unless stated otherwise. Certifications held by the provider:
These certifications belong to our providers and cover their infrastructure, not Finaxis. Provider names on request.
Policies are public; other documents on request.
Personal information, retention and rights.
Terms for using the platform.
Scope, testing rules and reporting address.
Issued at the end of the assessment.
Names and certification attestations.
Providers, their function and the data they process.
Your organization's questionnaire, completed by Finaxis.
30 controls, by area.
Hosted in Canada
Customer data hosted in Canada.
Encryption
Data encrypted in transit and at rest.
Customer separation
Every record belongs to one customer account. Access is checked on every request.
No resale
Data never sold or used for advertising.
Single sign-on
Google and Microsoft.
Passkeys
Passwordless sign-in (WebAuthn).
Two-factor authentication
Authenticator app, SMS or recovery codes.
Required 2FA
An administrator can require it for the whole account.
Passwords
Hashed, never stored in plain text.
Sign-in alerts
Email on every sign-in from a new device. Attempts are rate-limited.
Roles
Administrator, editor, viewer and guest. The Nova plan lets you create and manage more granular access roles than the Billie plan.
Permissions by data type
Separate rights for invoices, customers, users, mailboxes and the other data types.
Customer assignment
A user limited to the customers assigned to them.
Server-side enforcement
Permissions checked by the API, not just in the interface.
Activity log
Who did what, when and from where. Administrators only.
CASA Tier 2
Application tested by an authorized lab against the OWASP ASVS standard.
Static code analysis
On every code change.
Dependency scanning
Against known-vulnerability databases.
Weekly security review
Scan results reviewed every week.
Error monitoring
Continuous, with personal information scrubbed.
OAuth 2.0
QuickBooks, HubSpot, Google and Microsoft. Finaxis never receives your passwords.
Revocable at any time
In Finaxis, or in QuickBooks, HubSpot, Google or Microsoft.
Acomba agent
Transmission over HTTPS.
Authenticated sending domain
Reminders sent from your domain, connected to our sending servers through MX, DKIM and DMARC.
Private environment in Canada
Models deployed in a private environment, on infrastructure in Canada, unless stated otherwise.
No shared training
Your data trains no AI model shared across customers.
Values replaced
Where possible, amounts, due dates and the contact's first name replaced with placeholders in what the AI writes. Real values filled in afterwards by Finaxis.
Certified provider
Provider certifications listed under Compliance.
Public status page
status.finaxis.ai
Vulnerability disclosure
Public policy and security.txt file.
Permissions Finaxis requests for each connection.
| System | Connection | Used by Finaxis for | Permissions requested |
|---|---|---|---|
| QuickBooks Online | OAuth 2.0 | Invoices, customers and payments. |
|
| Acomba | Windows agent on your machine, transmission over HTTPS | Invoices, customers and payments. | No OAuth permissions |
| HubSpot | OAuth 2.0 | Reading the CRM. Adding the reminders Finaxis sends to the CRM. |
|
| Google Workspace (Gmail) | OAuth 2.0 | Sending reminders from your mailbox. Reading replies, if turned on. |
|
| Microsoft 365 (Outlook) | OAuth 2.0 | Sending reminders from your mailbox. Reading replies, if turned on. |
|
| Other mailbox | IMAP and SMTP | Sending reminders and reading replies. | No OAuth permissions |
| CSV file | Manual import | No standing connection. | No OAuth permissions |
* Only if Finaxis reads replies
Functions handled by providers. Named list, with the data processed, on request.
Hosting and storage
Servers and storage for the platform.
AI models
Writing and analysis by the agents.
Web search
Public information about your business customers, for the AI.
Email delivery
Reminders sent from a Finaxis address or your domain.
SMS delivery
SMS reminders and sign-in codes.
Error monitoring
Error detection, with personal information scrubbed.
Support
Tracking requests sent to our team.
Scope, testing rules, reporting address and Finaxis's commitments.
https://finaxis.ai/.well-known/security.txt
CASA Tier 2 letter of validation, providers, subprocessors and security questionnaire.
Necessary
Keep your session open, protect forms against bots and remember your choices.