FOLIO — SECURITY ARCHITECTURE, ENCRYPTION, COMPLIANCE

Security is structural.

Not procedural.

FinHelm holds no copy of your ledger. Every ERP read travels over an encrypted, read-only connection, is used for the analysis you requested, and is discarded — never warehoused. What persists is what you author in FinHelm and the forecast history your workspace builds.

For enterprise due diligence · III May MMXXVI
Product analytics disclosure updated XI September MMXXVI

SECTION ISecurity Overview

FinHelm Corp builds Probabilistic Finance™ products on a no-ledger-copy architecture: raw financial data from connected ERP systems is fetched live, processed for the requested analysis, and discarded, never warehoused. FinHelm stores what customers author in the product (budgets, driver sets, scenarios), forecast history, account and billing records, encrypted connection credentials, and audit metadata. This architecture materially reduces the data-exposure surface relative to traditional FP&A platforms that ingest and store full ledger copies.

FIG. I.a · The ledger boundary is structural, not procedural. The ledger we never store, we cannot lose.

SECTION IIArchitecture

SECTION IIIAuthentication

SECTION IVData Encryption

SECTION VAccess Control

SECTION VICompliance Posture

FIG. VI.a · FinHelm makes no representations regarding compliance certifications it has not earned. Aspirational items above are explicitly marked.

SECTION VIISub-Processors

Sub-processor Purpose Data
Amazon Web ServicesInfrastructure, identity, key managementEncrypted application data and tokens
Anthropic, PBC(a) Claude.ai as MCP client; (b) Claude models accessed server-side via AWS BedrockTool calls and summarized financial context
Intuit Inc.QuickBooks Online ERP integrationOAuth tokens and customer-authorized financial data
DualEntryERP integrationOAuth tokens and customer-authorized financial data
RilletERP integrationOAuth tokens and customer-authorized financial data
StripePayment processingPayment instrument data (handled entirely by Stripe)
VercelFrontend hostingStandard web logs
PostHogProduct and journey analytics, visitor profiles, heatmaps, masked session replay and diagnostics with an opt-out; limited public-request delivery measurementBrowser activity and details, IP and approximate location, masked recordings, confirmed contact and account details, billing and email delivery outcomes, sanitized errors and tool timings; public-request records use hashed identifiers without person profiles; no ledger data or message bodies
Google AnalyticsPublic marketing analytics, on by default with the same opt-outSelected page names, confirmed contact submissions, browser/device and session information; no ERP data or form contents

PostHog: Product analytics is on by default on selected website and product pages unless you have declined it or enabled Do Not Track or Global Privacy Control. We collect visits, clicks, form change or submit actions without entered values, scrolling, page time and exits, and heatmaps. Visitor profiles include browser/device details and user-agent strings, IP address, approximate location and visit sources. After a confirmed contact or assessment submission with analytics allowed, we link visits to the submitted email and available contact and company details. Verified sign-ins with analytics allowed use stable account identifiers. Server tracking records confirmed lead saves, account visits, billing and email delivery outcomes, sanitized errors and tool-call timings. Saved lead and account choices control later linked server events.

Session replay is enabled for all eligible sessions. Recordings include page layout, public text and interactions, with all form values masked. Text in signed-in product pages and financial or user-content areas of the assessment is masked; embedded frames, canvases and designated private visualizations are blocked. Sign-in and other excluded pages, financial inputs and results, ledger data, message bodies, payment credentials, passwords, sign-in tokens, console logs and network request or response contents are excluded. Tool diagnostics exclude prompts, arguments and results. Use Privacy choices to allow or decline analytics and recording. Your saved browser choice remains until you change it or clear browser storage. Clearing browser storage removes the local choice, while a saved account decline can apply again at sign-in. Separately, limited public-request delivery records use hashed client identifiers without person profiles and exclude private routes, queries, bodies and runtime messages. See the Privacy Policy, Section IV for details.

Google Analytics: Analytics is enabled by default on selected public marketing pages, using the same Privacy choices and browser privacy signals. Assessment, account and sign-in pages are excluded. We send predefined page names and confirmed contact submissions, with a limited product-tier category. Google may also process browser/device information, session activity and approximate location. Its first-party identifier cookies are configured to expire after 180 days without refreshing that period on a visit. Form contents, financial values, account identifiers, raw query strings and referring URLs are excluded; advertising features and automatic form, search and click measurement are disabled. See the Privacy Policy, Section IV.

FIG. VII.a · The canonical sub-processor list is maintained at finhelm.ai/privacy/.

SECTION VIIIData Residency

SECTION IXBreach Notification

In the event of a confirmed security incident affecting customer data, FinHelm will notify affected customers without undue delay and in any case within seventy-two (72) hours of confirmation, consistent with prevailing standards under GDPR and U.S. state breach-notification laws. Notification will identify, to the extent then known, the nature of the incident, the data affected, mitigation steps taken, and a point of contact.

SECTION XCustomer Rights

SECTION XIContact

FinHelm Corp · finhelm.ai

Probabilistic Finance™ · Always On Course.

FOLIO — INVITATION · ENTERPRISE DUE DILIGENCE

Bring your security checklist.

Vendor questionnaires, SOC 2 readiness updates, infrastructure deep-dives. We will answer the questions your CISO is paid to ask.