Compliance, control and an audit trail. Built in from day one, not bolted on.
Forward-deployed onboarding
A Finkraft finance engineer works alongside your team from data audit to go-live, and stays through the first close.
Dedicated engineer from day one
Vendor and invoice data cleaned before launch
ERP mapping done with your controller
SLA-backed production support
Runs where your ledger lives
Native connectors for the ERPs finance teams already run, plus API, SFTP and file upload for everything else.
Native connectors, API or SFTP
Swap ASPs without re-integrating
Multi-entity, multi-currency
The ledger stays yours
Security and governance
Every action is logged and traceable. Role-based access, audit trails and data residency controls are part of the core, so your risk team can sign off without a workaround.
ISO 27001ISO 27017ISO 27018SOC 2 Type 2PCI DSS Level 4VAPT reportsGDPRRole-based accessFull audit trailData residency · UAE & India
UAE
FTA e-invoicing via accredited providers, PINT AE, VAT recovery.
India
GSTN and IRP e-invoicing, ITC recovery, GSTIN validation.
Global
Multi-entity groups on one ledger, in every currency you bill in.
Certifications
Audited, certified and pen-tested.
Independent auditors test the controls, not just the paperwork. Certificates and the latest test summary are in the security pack.
Certificates, the SOC 2 report and the latest VAPT summary are shared under NDA.
Information security management across the platform and the people who run it.
ISO/IEC 27017
Cloud-specific controls on top of 27001, covering how we run in shared infrastructure.
ISO/IEC 27018
Handling of personally identifiable information processed in the cloud on your behalf.
SOC 2Type 2
SOC 2 Type 2
Controls tested over an observation window, not signed off at a single point in time.
PCI DSSLevel 4
PCI DSS Level 4
Card data handling for the payment flows behind corporate and virtual cards.
VAPTReports
VAPT reports
Vulnerability assessment and penetration testing by an independent firm, with findings tracked to closure.
FAQ
Common questions
A phased requirement for businesses to issue and receive structured electronic invoices through accredited service providers, reported to the tax authority. Dates are published by the authority and should be re-checked as they are updated.
Scope depends on revenue band and entity type. Use the readiness check to see which phase applies to you.
An Accredited Service Provider is a party authorised to transmit e-invoices in the five-corner model. Finkraft is not an ASP.
No. Finkraft is an independent readiness and integration layer. We help you assess, select and connect to the accredited provider that fits you, rather than locking you in.
The UAE application of the Peppol International Invoice (PINT) specification, which defines the structured format your invoices must follow.
Penalties and blocked invoice flows are set by the authority. We recommend treating the ASP appointment date as the operational deadline.
No. The goal is to make your current stack e-invoice ready. Finkraft sits alongside your ERP and syncs status back, so finance is never working in two systems.
SAP, Oracle, Microsoft Dynamics 365, NetSuite, Tally, Zoho Books, Xero and Odoo, through a native connector, API, SFTP or file upload. Only live integrations are listed at launch.
Yes. Flight and hotel booking is fully available in the UAE and India, and every booking arrives with a compliant invoice ready for VAT or GST recovery.
Eight questions, about three minutes. You see a score immediately; the detailed report is emailed to you.
Finkraft is ISO 27001, 27017 and 27018 certified and GDPR-aligned, with encryption in transit and at rest and role-based access across entities.
Developer documentation is planned for a later phase. Today, integrations run through native connectors, API, SFTP or file upload set up with our team.
Built for your role
Built around the job you actually do.
Same platform, different seat at the table. Pick yours to see what it takes off your plate.