Trust
How we handle your financial data.
This page is maintained by Finendra to answer common security and privacy questions about how we work. It describes our current practices — it is not a certification or an independent audit.
Encryption at Rest & in Transit
All data is encrypted using AES-256 at rest and transmitted using TLS 1.3 encryption. Internal document portals and databases enforce encrypted storage volumes.
Least-Privilege Role-Based Access
Team members receive least-privilege access restricted specifically to client engagement scopes. Client data is strictly segregated — team members can only access clients in their direct portfolio pod.
Zero Disbursement Authority (You Hold the Keys)
Finendra operates strictly in preparer mode. We reconcile accounts, draft payroll runs, and stage AP bills in Bill.com or Ramp, but we never hold authorization to wire funds or release payments. Sole disbursement approval remains with you.
Read-Only Banking Feeds
We never ask for or store your primary root banking passwords. Bank feeds and statement syncs are configured using read-only accountant view permissions or direct native API integrations.
Standard Mutual NDA & DPA
Every engagement includes a comprehensive Non-Disclosure Agreement (NDA) and Data Protection Agreement (DPA) executed prior to onboarding, guaranteeing strict confidentiality and full client data ownership.
Secure Multi-Factor Authentication (MFA)
All Finendra operational accounts enforce hardware or authenticator app-based 2FA/MFA, single sign-on (SSO), and breach-monitored password hygiene.
Delegated Accountant Invites
Access to QuickBooks Online, Xero, Gusto, Stripe, and Rippling is provisioned through native delegated 'External Accountant' invitations under your company's own master billing account.
Rapid Offboarding & Access Revocation
Upon engagement conclusion or transition, our access is immediately revoked, cached session tokens invalidated, and written confirmation provided within 24 hours.
Finendra is responsible for
- Enforcing AES-256 storage and TLS 1.3 transmission encryption
- Limiting internal access strictly to your assigned engagement pod
- Operating strictly in preparer mode without payment disbursement authority
- Executing standard NDA & DPA agreements prior to receiving financial data
- Maintaining audit logs of all access and entries made in client software
You are responsible for
- Granting delegated 'Accountant' or read-only access instead of sharing admin passwords
- Managing user permissions and dual-authorization payment approvals inside your banking portal
- Promptly revoking accountant access upon formal engagement offboarding
- Maintaining your own internal dual-control approval processes for disbursements
Reporting a security concern
If you believe you have found a vulnerability in this site, or you have a question about how your data is handled, email connect@finendra.com with the details. Please give us a reasonable window to investigate before disclosing anything publicly.
For how we collect and retain information, see our Privacy Policy.
Have a security questionnaire to complete?
Send it over and we will work through it with you as part of the discovery process.