Trust centre
Security & Data
A plain-language overview of the controls and providers currently used to run Finalizo. This page describes the product as it exists today; it is not a certification or security guarantee.
How Finalizo stores data
Finalizo stores the project closeout records, client details, resources, and sign-off evidence needed to provide the service. Application ownership checks limit access to the relevant account and project.
Authentication and client access
Owners authenticate through the configured Finalizo authentication providers. Clients use the access link included in their handover or sign-off email. Access links and pack passwords should be treated as confidential.
Credential protection
Credential passwords are encrypted before storage using AES-256-GCM. Passwords are not included in standard account exports or email payloads. A client reveal is an explicit action and is recorded with an access event.
File and resource storage
Uploaded project resources are handled through the configured UploadThing integration. Finalizo presents the resource links and metadata needed for the closeout workflow; users remain responsible for the content they upload.
Analytics and monitoring
PostHog is used for product analytics and Sentry for error monitoring. Sensitive fields, credentials, cookies, authorization headers, and secret-bearing routes are redacted or filtered by the application safeguards.
Email providers
Transactional email is sent through Resend. Authentication emails are operational messages and are not configured with product open or click tracking.
AI processing
For structured closeout suggestions, Finalizo automatically supplies only approved non-secret project fields. The project-draft feature also accepts user-written text and sends that text to the configured AI provider to fulfil the request; do not enter passwords, tokens, API keys, private keys, or other secrets.
Subprocessors and payments
The current application integrates with Supabase/PostgreSQL infrastructure, Resend, UploadThing, Stripe, PostHog, Sentry, Google OAuth, and an AI provider for the features described above. Provider terms and availability apply.
Retention, deletion, and export
Finalizo provides account export and account deletion controls. Exported credential data is metadata-only; encrypted values and secret-capable notes are excluded. Structured export does not necessarily package every uploaded external file or asset. Retention can also be affected by operational, legal, billing, and provider requirements, so this page does not promise a universal deletion timeline.
Security contact
Report a suspected security issue to security@finalizo.com. For privacy questions, contact privacy@finalizo.com. Finalizo is operated by Nebula Craft Design Ltd.
For formal terms and privacy details, see Privacy and Security Policy.