SOC2C

Is this your company? Buyers are checking Fintoc here. Claim fintoc.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Fintoc logo

Fintoc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Fintoc is SOC 2 compliant. Fintoc also holds ISO 27001, and PCI DSS.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

Fintoc provides reliable, scalable financial infrastructure for companies to receive and manage payments with ease. Because we work with sensible data, security is a top priority at Fintoc. Our platform uses the highest security standards to protect our customers’ information and privacy at every step of the process.

Compliance & infrastructure

Hosting
GCP

Subprocessors

2
  • G
    Google Cloud Platform · Cloud infrastructure
    United States
  • C
    Cloudflare · Traffic Routing & CDN
    Global

Compliance leadership

The person who leads Fintoc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Fintoc's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Fintoc SOC 2 compliant?
Fintoc is SOC 2 compliant. On SOC2C this listing is Listed.
Is Fintoc ISO 27001 certified?
According to Fintoc's public trust center, Fintoc is ISO 27001 certified. On SOC2C this listing is Listed.
Is Fintoc PCI DSS compliant?
According to Fintoc's public trust center, Fintoc is PCI DSS compliant. On SOC2C this listing is Listed.
Can I use Fintoc's SOC 2 for a vendor risk assessment?
Yes. Fintoc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Fintoc penetration tested?
Fintoc hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Fintoc

Reproduced from Fintoc's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Where is Fintoc's infrastructure hosted?
Our infrastructure is hosted on Google Cloud Platform (GCP). GCP is currently the gold standard in terms of data center security and availability, with strict access control measures and multiple redundancies that guarantee the uninterrupted operations of Fintoc’s services. We deploy our infrastructure in three redundant data centers and have an automated, zero-downtime failover mechanism in the unlikely case of a data center outage. Our Datacenters comply with major compliance and regulation programs, including ISO 27001, PCI-DSS, and SOC 2.
How Fintoc secures banking data?
Fintoc is a safe platform that was designed from the ground up to store and encrypt banking credentials. At all points in time, Fintoc encrypts data in-flight and at rest using strong encryption. For symmetric encryption and credentials storage, we use AES256 cipher. All traffic is encrypted with a minimum supported TLS version of 1.2. Fintoc employs HTTP Strict Transport Security (HSTS) with a max-age of 1 year with preloading enabled. Cloudflare is configured with the TLS encryption mode "Full (strict)". All of Fintoc's servers run within private VPCs on GCP.
Want to report a potential security issue?
If you believe you’ve discovered a security vulnerability or need to report a potential security incident, please contact us at security@fintoc.com. Our security team continuously monitors this mailbox and will: - Acknowledge receipt of your report promptly. - Investigate the issue in accordance with our Incident Response Policy. - Keep you updated on progress and resolution steps. For sensitive reports, we encourage the use of secure channels (available upon request). Please include as much detail as possible to help us triage quickly (e.g., steps to reproduce, affected systems, and any relevant logs or screenshots). We greatly appreciate responsible disclosure and are committed to working with reporters to resolve issues quickly and securely.