Data, privacy, and security at Finn

What we store, where it lives, who can see it, and how to run Finn inside your own perimeter.

Funds ask us the same handful of questions, usually in the same order. What do you store? Where does it live? Who can see it? Does it train your models? Can we run it inside our own walls? Here are the answers. Where one depends on how you deploy Finn, we say so.

The short version: Your data is kept separate for each client. We don’t share it, sell it, or use it to train models for anyone else.

What Finn actually holds

Finn is only useful because it knows your book, so it holds a fair amount: your positions and watchlist, the thesis you keep on each name, the notes and reports it writes for you, and whatever research you forward its way. That adds up. Over time you end up with a private research corpus that’s yours to keep.

Because that corpus is the whole point, we don’t hedge on how we treat it:

Your data is kept separate. Each client’s portfolio, theses, and corpus sit on their own. No shared pool, no cross-client search, nothing pooled across funds.

We don’t train on your data. Finn learns your style from your own corpus and memory, and it uses that for you alone. Nothing you send improves another client’s results, and nothing is shared or sold.

Market data is licensed, not scraped. Fundamentals, filings, and news come from licensed institutional providers. You’re not basing research on feeds nobody can vouch for, and your compliance team isn’t being asked to sign off on one.

Why running on email helps compliance

Finn runs on email and your calendar instead of yet another platform. Some of that is about workflow, but it also settles a compliance question. Everything Finn sends or receives goes through the channel your firm already archives and supervises. There’s no separate chat log sitting outside your retention system, no new tool for IT to vet, nothing extra to reconcile at audit time. Your existing archive already holds the full record.

The same setup keeps Finn on the right side of the regulatory line. It produces analysis, not investment advice. It doesn’t place trades, route orders, or connect to a broker. For a regulated fund, Finn belongs in the same box as a junior analyst’s written work: something you can review, archive, and keep well clear of the execution chain.

Deployment options

Perimeter requirements vary from fund to fund, so Finn runs three ways:

Standard (SaaS). Segregated tenancy on our own infrastructure. It’s the quickest way to get started and fits funds whose policies allow vetted outside SaaS. This tenancy runs on AWS in the United States.

Private cloud. A dedicated environment for data-residency needs, in your region and jurisdiction. Scoped per engagement.

Dedicated deployment. For funds that can’t use shared infrastructure at all, we offer a fully dedicated deployment, subject to scope. Bring your security team and we’ll map Finn’s architecture against your requirements.

Mode

Where it runs

Best for

Standard (SaaS)

Segregated tenancy on Finn’s infrastructure (AWS, US)

Fastest path; funds that permit vetted external SaaS

Private cloud

Dedicated environment in your region / jurisdiction

Data-residency requirements; scoped per engagement

Dedicated deployment

No shared infrastructure at all

Strictest infosec perimeters; subject to scope

Model providers and subprocessors

Finn runs on models from OpenAI, Google, and Anthropic, with review at several stages rather than a single pass through one model. We use their business API tiers, which don't train on the data you send and hold it only briefly for abuse monitoring before deleting it. A current subprocessor list is available on request.

Retention and deletion

Your corpus is there to serve you, and it leaves when you do. When an engagement ends, we delete client data on request.

Security review and due diligence

We complete security questionnaires and operational due-diligence requests as part of onboarding, and we’ll walk your security team through the architecture under NDA.

The bottom line

Your portfolio, theses, and corpus stay separate, and we never share them, sell them, or train anyone else’s models on them. Finn’s output moves through the email you already archive, inside the workflows your compliance stack already watches. It analyses; it doesn’t recommend trades or place them. And if your infosec rules mean Finn has to live inside your own perimeter, that’s what the private-cloud and dedicated options are for.

To go deeper, request access and note that you want a security review, we’ll walk your team through the architecture under NDA.