Security & Trust
The controls, encryption, data residency and audit posture behind FinHub — documented for BFSI procurement, risk and compliance teams, not just engineers.
Controls
What's built into every layer
Six control families cover the full path of a verification or consent event — from the TLS handshake to the audit log entry.
Encryption everywhere
Every request between your systems and FinHub travels over TLS 1.2 or higher with modern cipher suites, and everything we persist — verification results, consent artefacts, configuration — is encrypted at rest with AES-256. Keys live inside a managed key-management boundary, are rotated on schedule and never appear in application code, so plaintext is not exposed even in backups.
Access control
Access follows least privilege by default. Dashboard users get role-based permissions scoped to what their job requires; API keys are scoped per environment and per product, and can be rotated or revoked instantly. Internally, production access is limited to a small on-call group, protected by multi-factor authentication and reviewed on a recurring schedule.
PII masking
Personally identifiable data — PAN, Aadhaar-linked identifiers, bank account numbers, phone numbers — is masked in logs, dashboards and internal analytics as standard. Full values surface only inside the verification flow that genuinely needs them, and never land in debugging output. What engineers and support staff see day-to-day is the masked form, not raw identity data.
Audit logging
Every API call, consent decision, configuration change and admin action is written to an append-only audit log with a tamper-evident timestamp. Logs are retained per policy and exportable in machine-readable formats, so when your internal audit, RBI inspection or DPDP review asks what happened and when, the answer is a query — not an archaeology project.
Infrastructure
FinHub runs on hardened, India-region cloud infrastructure with network segmentation between environments, no direct public access to data stores, and infrastructure defined as code so changes are reviewed like any other release. Redundant deployments across availability zones back the platform's 99.9% uptime commitment, with automated failover and tested recovery procedures.
Monitoring & response
The platform is monitored around the clock for availability, error rates and anomalous access patterns, with alerts routed to an on-call rotation rather than a shared inbox. A documented incident-response runbook defines severity levels, escalation paths and customer notification steps, and post-incident reviews feed fixes back into the controls above.
Certifications & Standards
Honest about where we stand
We describe our compliance posture precisely — what we operate today, what we're working toward, and which regulatory frameworks shaped the architecture.
Aligned with ISO 27001 practices
Our security management follows ISO 27001 practices — asset inventories, risk assessments, documented policies and periodic access reviews — operated as day-to-day discipline, not a once-a-year exercise.
SOC 2 readiness on our roadmap
SOC 2 readiness is on our roadmap. The underlying controls for security, availability and confidentiality are already in operation and documented, so procurement teams can review them today.
RBI, UIDAI & SEBI-aligned architecture
The platform is architected around RBI outsourcing expectations, UIDAI rules for Aadhaar-linked data handling and SEBI norms — so your compliance team reviews familiar patterns, not surprises.
We never claim a certification we do not hold. Ask us for current status and supporting documentation during your procurement or vendor-risk review.
Data residency in India
Data processed through FinHub is handled and stored on India-region infrastructure — verification results, consent artefacts and audit trails included. That keeps you aligned with the data-residency expectations of Indian financial regulators and with the DPDP Act’s direction of travel. The architecture is DPDP-ready by design: consent, purpose limitation and auditable records are part of the core platform, and our DPDP governance platform turns them into a full compliance workflow. New to the law? Start with our DPDP compliance guide.
Encryption, specifically
In transit, everything runs over TLS 1.2 or higher — API traffic, dashboard sessions and internal service calls alike. At rest, data is encrypted with AES-256, backups included. Keys are held in a managed key-management service, rotated on schedule and separated from the data they protect. And because logs are where encryption promises usually leak, PII is masked in logs, traces and dashboards by default.
Responsible disclosure
Security researchers make platforms like ours safer, and we welcome their work. If you believe you’ve found a vulnerability in FinHub, email info@habilelabs.io with reproduction steps and impact. We acknowledge reports promptly, keep you informed through triage and remediation, and will not pursue action against good-faith research that respects user data and avoids disrupting the service.
Operating record
Security that holds up under production load
The same platform that carries these numbers carries the controls on this page — one integration, one SLA, one audit trail.
0.0%
Uptime commitment
0+
Verification APIs
<0 min
To first integration
FAQ
Security questions, answered
The questions BFSI procurement, risk and infosec teams ask us most often.
Data processed through FinHub is handled and stored on India-region cloud infrastructure. Verification results, consent records and audit logs stay within Indian data-centre regions, supporting the data-residency expectations of Indian financial regulators and your own outsourcing policies.
Keep exploring
Related resources
Need a security review?
Request our security documentation and compliance summary for procurement and vendor-risk review.