Security

Your financial data. Treated accordingly.

Your P&L, cash position, and cost centre data are some of the most sensitive figures in your organisation. This page describes exactly how Fintower stores, protects, and controls access to that data — without the marketing language.

Security controls

Data Residency

Your financial data is stored in EU-based infrastructure (Sweden / Netherlands). We do not transfer data outside the EEA. Fintower is registered in Sweden and subject to Swedish data protection law, GDPR, and the ePrivacy Directive. We can provide a Data Processing Agreement (DPA) to all paid-plan customers on request.

Encryption

All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256. Database backups are encrypted and stored with the same protections as primary data. Encryption keys are managed using a dedicated key management service — not stored alongside the data they protect.

Access Control

Role-based access control is built into every Fintower plan. Administrators assign permissions per user — read-only, report access, or full platform access. An audit log records every data pull, export, and permission change. Single Sign-On (SSO via SAML 2.0) is available on the Enterprise plan.

Compliance Posture

Fintower is a Swedish company and operates under GDPR as its baseline compliance framework. We designed our data architecture on privacy-by-design principles from day one — data minimisation, purpose limitation, and EU residency are not afterthoughts. SOC 2 Type II audit is on our compliance roadmap — the controls are in place and we are working toward formal certification. We do not currently hold SOC 2 certification. If this is a requirement for your organisation, please contact us directly to discuss our controls documentation.

Security Questions

Security review for Enterprise customers

If your data protection officer or procurement team requires a security review before approval, we provide detailed architecture documentation, a custom Data Processing Agreement, and a direct call with our engineering team. We do not hide behind a generic security questionnaire.

Contact our team