How we keep your data confidential, available and protected: the controls, the processes and the people behind them.
July 2, 2026
August 1, 2026
4.0
This document is published by Fininvo, a trade name of Prashbi Global Services Pvt. Ltd., a company incorporated under the laws of India (CIN: U52100KA2020PTC133490), with its registered office at Tholons Tower, 346 HIG, 17th Cross Rd, Dollars Colony, R.M.V. 2nd Stage, Bengaluru, Karnataka 560094, India. References to "Fininvo", "we", "us", or "our" in this document refer to Prashbi Global Services Pvt. Ltd..
Security is built into every Fininvo product (ERP, HRMS, Payroll, Jobs, Recruit) and our mobile apps. We operate layered controls covering data protection, infrastructure, application security, access, personnel and monitoring, backed by a documented incident response process and a public responsible disclosure programme. This page summarises the programme; the contractual commitments are in the Data Processing Agreement (Annex II). Enterprise customers may request our detailed security packet, penetration test summaries and questionnaire responses under NDA from security@fininvo.com.
AES-256 for databases, file storage and backups, using managed key services with rotation.
TLS 1.2 or higher (TLS 1.3 preferred) for all connections; HSTS on web properties.
Every tenant is logically isolated. Tenant scoping is enforced in the application and data layer on every query, and verified in code review and testing.
Automated daily encrypted backups with defined retention and periodic restore testing.
Secrets and keys held in managed secret stores, never in source code; scoped per environment.
Purpose-bound retention with deletion workflows for account termination and data subject requests; backups expire in the ordinary rotation cycle.
The platform runs on ISO 27001 and SOC 2 certified cloud providers (Amazon Web Services and Microsoft Azure), with primary data residency in India and additional regions as configured. Physical data centre security is inherited from those providers.
We identify vulnerabilities through automated scanning, dependency monitoring, code review, penetration testing and our responsible disclosure programme. Remediation targets by severity:
| Severity | Remediation target |
|---|---|
| Critical | Mitigation within 72 hours of confirmation |
| High | Within 7 days |
| Medium | Within 30 days |
| Low | Within 90 days or the next scheduled release |
Independent penetration tests are performed at least annually and after material architectural change. Executive summaries are available to enterprise customers under NDA.
We monitor the platform continuously with centralised logging, error tracking and alerting on anomalous behaviour. Our documented incident response process covers detection, triage, severity classification, containment, eradication, recovery and post-incident review with corrective actions.
Breach notification. If a personal data breach affects your data, we notify you without undue delay, and in any event within 72 hours of becoming aware, with the content described in the DPA, and we assist with your own regulatory notification duties.
Card payments are processed by PCI DSS Level 1 certified gateways (Razorpay in India, Stripe elsewhere). Card numbers and CVV codes are captured directly by the gateway and are never stored on Fininvo systems. Recurring payments in India follow the RBI e-mandate framework with pre-debit notification.
Our security programme is aligned with ISO 27001 and SOC 2 Type II, and formal certification is in progress; we will update this page as certifications are obtained and will not claim a certification we do not hold. Our cloud providers (AWS, Microsoft Azure) and payment gateways hold their own ISO 27001, SOC and PCI DSS certifications. Data protection compliance (GDPR, DPDP Act 2023) is described in the Privacy Policy and DPA.
If you believe you have found a security vulnerability, please report it privately under our Responsible Disclosure programme or via /.well-known/security.txt. We acknowledge reports within 3 business days and offer safe harbour for good-faith research.
Security Team
security@fininvo.comData Protection Officer
dpo@fininvo.comRegistered Office
Prashbi Global Services Pvt. Ltd.
Tholons Tower, 346 HIG, 17th Cross Rd, Dollars Colony,
R.M.V. 2nd Stage, Bengaluru, Karnataka 560094, India
CIN: U52100KA2020PTC133490