Security
Your financial data. Treated accordingly.
Your P&L, cash position, and cost centre data are some of the most sensitive figures in your organisation. This page describes exactly how Fintower stores, protects, and controls access to that data — without the marketing language.
Security controls
Data Residency
Your financial data is stored in EU-based infrastructure (Sweden / Netherlands). We do not transfer data outside the EEA. Fintower is registered in Sweden and subject to Swedish data protection law, GDPR, and the ePrivacy Directive. We can provide a Data Processing Agreement (DPA) to all paid-plan customers on request.
Encryption
All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256. Database backups are encrypted and stored with the same protections as primary data. Encryption keys are managed using a dedicated key management service — not stored alongside the data they protect.
Access Control
Role-based access control is built into every Fintower plan. Administrators assign permissions per user — read-only, report access, or full platform access. An audit log records every data pull, export, and permission change. Single Sign-On (SSO via SAML 2.0) is available on the Enterprise plan.
Compliance Posture
Fintower is a Swedish company and operates under GDPR as its baseline compliance framework. We designed our data architecture on privacy-by-design principles from day one — data minimisation, purpose limitation, and EU residency are not afterthoughts. SOC 2 Type II audit is on our compliance roadmap — the controls are in place and we are working toward formal certification. We do not currently hold SOC 2 certification. If this is a requirement for your organisation, please contact us directly to discuss our controls documentation.
Security Questions
Security review for Enterprise customers
If your data protection officer or procurement team requires a security review before approval, we provide detailed architecture documentation, a custom Data Processing Agreement, and a direct call with our engineering team. We do not hide behind a generic security questionnaire.