For accountancy practices there is no compromise on security

Finteli is built for accountancy practices handling sensitive client data. Our application and this marketing website apply layered controls, from tenant isolation and audited AI workflows to HTTPS-only delivery and minimal third-party tracking.

AI privacy

How the Finteli application handles data sent to AI providers.

  • No model training

    Your data never trains or improves shared AI models.

  • Full data isolation

    Strict tenant separation with row-level security.

  • Traceable AI

    Every agent step is logged and auditable.

  • Human review first

    AI output stays in review until your team approves it.

  • No selling or sharing

    Firm and client data is never sold or used for ads.

  • Data deletion

    Remove your data on request at any time.

Secure by design

Core application controls for authentication, access, and storage.

  • Managed authentication

    Sign-in is handled by a dedicated identity provider; the API validates every request.

  • No credential storage

    No stored passwords - calendar access uses revocable OAuth only.

  • Encrypted in transit

    HTTPS/TLS on every connection.

  • Organisation-scoped access

    Access controls and organisation boundaries on all protected routes.

  • Upload safeguards

    Size limits and private, organisation-scoped storage for client files.

  • Subprocessor oversight

    Named subprocessors, purposes, and locations are available in your DPA or on request.

This website

How we protect visitors to finteli.co - separate from the signed-in product.

  • HTTPS only

    This site is served over encrypted connections.

  • No ad or analytics cookies

    No Google Analytics, PostHog, or advertising pixels.

  • Minimal third parties

    Form handling, Cloudflare Turnstile bot protection on forms, and font delivery only; no advertising or analytics scripts.

  • Hosting security logs

    Our hosting provider processes delivery and security logs only.

  • No browser tracking storage

    No localStorage or sessionStorage for tracking.

Security operations

How we respond to issues and govern third-party services.

  • Subprocessor oversight

    Enterprise providers with transfer safeguards where required.

  • Licence and contracts

    Terms and retention set out in your software licence agreement and DPA.

Documentation & compliance