
Security and compliance
Built for the scrutiny it will face.
What we do today, what we are certified for, and what we have committed to — with dates. Where something is in progress we say so and give the milestone. Where something does not exist yet, this page says that too.
Certification status
Finvica is a new platform and does not yet hold the certifications an established vendor would. Rather than describe the programme in the abstract, the table below gives each item, its scope and the date it completes. A dated commitment is the only version of this that survives a diligence call.
| Item | Status | Scope | Next milestone |
|---|---|---|---|
| ISO/IEC 27001 | Audit in progress | Information security management system, platform and operations | Completing end-September 2026 |
| ISO/IEC 27017 and 27018 | Scheduled | Cloud security and cloud privacy controls | Follows 27001 certification |
| DPDP Act 2023 programme | In progress | Data principal rights, consent, breach process, retention | Complete by 30 September 2026 |
| Penetration test (VAPT) | Scheduled | Application and infrastructure, independent tester | Summary published here when the report exists |
No certification is claimed here before it is issued. When ISO 27001 completes, the certificate number and issuing body replace the status row above.
Data residency
This section is being written against the audited infrastructure and ships with the security lead’s sign-off. It is left empty rather than filled with plausible values — on this page more than any other, a claim that does not survive verification costs more than a gap.
Encryption
This section is being written against the audited infrastructure and ships with the security lead’s sign-off. It is left empty rather than filled with plausible values — on this page more than any other, a claim that does not survive verification costs more than a gap.
Access control
Access follows the four-level hierarchy the whole platform is built on — group, family, client, account. A user sees the part of the book their role and position entitle them to and nothing beyond it, which means a relationship manager cannot browse a colleague’s clients and a branch cannot see another branch.
Single sign-on is supported through your existing identity provider, so joiners and leavers are handled where you already handle them rather than in a second place you have to remember.
This section is being written against the audited infrastructure and ships with the security lead’s sign-off. It is left empty rather than filled with plausible values — on this page more than any other, a claim that does not survive verification costs more than a gap.
Audit and logging
Sensitive actions write an immutable audit entry — who did it, what changed, and when. The trail is designed to be produced for a regulator rather than read by an engineer, which means it is exportable and legible without a query tool.
This section is being written against the audited infrastructure and ships with the security lead’s sign-off. It is left empty rather than filled with plausible values — on this page more than any other, a claim that does not survive verification costs more than a gap.
Regulatory alignment
Finvica is a technology platform, not a registered intermediary. It does not hold an ARN, does not advise, and does not solicit investments. Firms using the platform transact under their own ARN or RIA registration and remain the regulated party in their own relationships.
EUIN validity is enforced at order entry, KYC runs against the KRA inside onboarding rather than beside it, and the transaction record carries the trail a PMLA review expects. The regulatory position in full — including the grievance officer — is on the regulatory page.
Availability
This section is being written against the audited infrastructure and ships with the security lead’s sign-off. It is left empty rather than filled with plausible values — on this page more than any other, a claim that does not survive verification costs more than a gap.
Subprocessors and vendors
This section is being written against the audited infrastructure and ships with the security lead’s sign-off. It is left empty rather than filled with plausible values — on this page more than any other, a claim that does not survive verification costs more than a gap.
Your data on exit
Nobody in this category addresses leaving, and every serious buyer thinks about it before signing. The principle is simple and worth stating before the detail is finalised: the book is yours, and getting it out is a supported operation rather than a negotiation.
This section is being written against the audited infrastructure and ships with the security lead’s sign-off. It is left empty rather than filled with plausible values — on this page more than any other, a claim that does not survive verification costs more than a gap.
Questions from diligence.
Do you hold an ARN, or act as an intermediary?
No. Finvica is a technology provider and not a registered intermediary. We do not hold an ARN, do not run a distribution business, and do not own the investor relationship. Distributors on the platform transact under their own ARN or RIA registration.
Can I get a copy of your security documentation for diligence?
Yes. Ask on the demo call or through contact sales and we will send what exists today, including the current certification status in writing. We will also tell you plainly what does not exist yet.