Security, privacy & AI transparency

This page is maintained by the Finthriva team to answer common security and privacy questions about the product. It describes controls that are live today — it is not an independent certification.

Security by default

Your money data, locked down

These are controls that are live in the product today — not marketing promises.

Encrypted in transit & at rest

Every request runs over TLS and all records are stored on encrypted managed Postgres.

Row-level data isolation

Database policies scope every row to your account — no other member can read your records.

No card details stored

Card payments are handled by Paystack. Finthriva never sees or stores your card number.

Signed webhooks only

Payment and banking callbacks are rejected unless the cryptographic signature matches.

Authenticated AI calls

AI tools run server-side behind your session with per-plan usage limits — never from the browser.

You control what you share

Statement uploads and AI analyses are tied to your account and can be deleted at any time.

How our AI works

How this AI recommendation was made

Model: Google Gemini (via server-side gateway)

Frequently asked questions

Shared responsibility: Finthriva secures the platform and your account data. You are responsible for keeping your password safe, and for how you act on AI guidance. Regulated decisions should be reviewed with a licensed professional.