Security and trust
Where your data lives, and what we have in writing.
Finio is a new company asking for a connection to your ledger. That is a reasonable thing to be careful about, so this page says what is settled and marks what is not.
The facts
Six things a security review asks first.
Anything marked on request is a document we will send you rather than a claim we are making on this page.
Where your data lives
Stored in the UK: the database, the application and your uploaded documents all run on DigitalOcean in London. Where the document-reading services run is named in the sub-processor list.
Signing in
Anyone who can see the ledger — finance, and a practice working across clients — signs in with a second factor: an authenticator app, enrolled on first login and asked for after. Site staff sign in with an email and a password, because someone mid-shift is not going to set up an authenticator app on the spot, and the ops side reaches nothing but its own deliveries.
What we connect to
Xero, through its published OAuth flow. The connection is granted by you and revocable by you from inside Xero at any time, without going through us.
Who a document is really from
A supplier is identified by what only they can print — their company number, their VAT number, their own address — never by ours, which appears on every document any supplier sends us and so proves nothing. VAT numbers are checked rather than trusted. A document that cannot be placed waits for a person instead of being filed against the nearest-looking match.
Model learning
Nothing Finio knows about your suppliers is learned by a model. Coding is decided by deterministic rules — fixed rules, the same output from the same inputs — built from your own invoice history, and no customer data is used to train or aid machine learning. Xero has confirmed in writing that this approach is acceptable under its Developer Platform Terms; the confirmation is shared on request.
Sub-processors
Named in full: DigitalOcean hosts the database, the application and the file storage, all in London. Documents are read by Anthropic (US) and Mistral (EU). Postmark receives inbound email and Resend sends outbound. This website counts visits with Google Analytics, and only where the visitor has allowed it. The same list, with regions and purposes, is in our security pack.
GDPR and our DPA
On requestWe act as processor for the ledger and document data you connect. A data processing agreement is available and can be signed before any connection is made.
ICO registration
Finio is a trading name of KRBUK Limited, which is registered with the Information Commissioner's Office under ZC076226 — checkable on the ICO's public register, where the entry appears under the company name.
How we work
Four practices, stated plainly.
Read before write
The Xero connection is used to read your chart of accounts and existing records before anything is posted. Nothing is written until you have seen what it would write.
Revocable at source
Disconnecting is done from inside Xero rather than by asking us. We cannot hold a connection you have withdrawn.
Documents are not a product
Your invoices are processed to produce your data. They are not sold, shared, used to train machine-learning models, or used to build anything anyone else benefits from.
Ask us anything before you connect
If your own security review needs something that is not on this page, send it to us and we will answer it in writing rather than on a call.
We do not hold any yet, and we are not going to imply otherwise.
No ISO 27001, no SOC 2, no Cyber Essentials badge on this page. They take time and money that a company at this stage has not spent yet. If a certification is a hard requirement for your review, tell us — it is useful for us to know which one and by when.
Send us your security questions.
Or email them to info@getfinio.co.uk and we will answer in writing.