Certified, encrypted, auditable.
Finkraft is ISO 27001, 27017 and 27018 certified, SOC 2 Type 2 audited, PCI DSS Level 4 compliant and GDPR-aligned, with independent penetration tests on top. Security is part of the core, so your risk team can sign off without a workaround.




Audited, certified and pen-tested.
Independent auditors test the controls, not just the paperwork. Certificates and the latest test summary are in the security pack.
Certificates, the SOC 2 report and the latest VAPT summary are shared under NDA.

ISO/IEC 27001
Information security management across the platform and the people who run it.

ISO/IEC 27017
Cloud-specific controls on top of 27001, covering how we run in shared infrastructure.

ISO/IEC 27018
Handling of personally identifiable information processed in the cloud on your behalf.
SOC 2 Type 2
Controls tested over an observation window, not signed off at a single point in time.
PCI DSS Level 4
Card data handling for the payment flows behind corporate and virtual cards.
VAPT reports
Vulnerability assessment and penetration testing by an independent firm, with findings tracked to closure.
Four statements you can put in front of an auditor.
Encryption in transit and at rest
TLS 1.2+ on every connection; data at rest encrypted with keys managed per region.
Role-based access across entities
Roles are scoped by entity, property or project. Approvers see what they approve, nothing more.
Full audit trail
Every capture, match, approval, payment and recovery file is logged with who, when and what changed.
Data residency
UAE customers are hosted in the UAE, Indian customers in India. The residency statement is available on request.
Security and governance
Every action is logged and traceable. Role-based access, audit trails and data residency controls are part of the core, so your risk team can sign off without a workaround.
