Trust and Security at FinDock
At FinDock, we place utmost importance on security, underscoring our commitment to trust and the protection of our customers’ data. Our actions demonstrate more than just a commitment; they are a continuous effort to enhance the robust security measures we have in place. By maintaining high security standards and reinforcing our protocols, we ensure the integrity and confidentiality of the data we manage. This dedication is a cornerstone of our operations, ensuring that we provide secure, reliable, and trustworthy solutions for our partners and customers.
Certifications
SOC 2 Type II
FinDock has completed an independent SOC 2 Type II audit under the ISAE 3000 standard. This audit assesses the design and operating effectiveness of controls related to security, availability, and confidentiality over a defined period of time. The certification confirms that FinDock maintains robust processes and safeguards to protect customer data and ensure the reliability of its services.
The certificate can be requested via infosec@findock.com.
ISO/IEC 27001:2022 certificate
ISO/IEC 27001:2022 is a globally recognized standard for information security management, laying out how to manage, implement, maintain, and boost an information security management system (ISMS). Getting this certification means passing an extensive audit by an official accredited auditor who verifies the way FinDock takes care of the confidentiality, integrity, availability of the data processed by FinDock.
For FinDock’s implementation partners, the certification confirms enhanced confidence in integrating FinDock solutions into their projects. It assures them of collaborating with a partner maintaining an Information Security Management System (ISMS) that meets international standards. Similarly, for customers, the ISO certification proves that their payment data is protected by robust security protocols and that they are working with the solution of a company committed to security and trust.
The certificate can be requested via infosec@findock.com.
PCI DSS
The Payment Card Industry Data Security Standards (PCI DSS) is an information security standard designed to ensure that companies processing, storing, or transmitting payment card information maintain a secure environment. Customers shall not transmit cardholder or sensitive authentication data (as those terms are defined in the PCI DSS standards) unless such data is message-level encrypted by the customer.
FinDock is assessed by a PCI DSS QSA as a Level-1 Service Provider against PCI DSS 4.0. The Attestation of Compliance can be requested using infosec@findock.com.
GDPR Compliance
FinDock is also fully compliant with the General Data Protection Regulation (GDPR), ensuring the highest standards of data privacy and security.
Support for security, privacy, and procurement reviews
Use the steps below to request documentation, submit questionnaires, and connect with our payment and security experts.
Step 1
Start with the overview
Step 2
Request in-depth reports
Email infosec@findock.com to request SOC reports, certificates, policies, and supporting documentation. We’ll confirm what’s needed and provide an NDA if required.
Step 3
Submit your questionnaire
If you have a vendor security questionnaire (SIG/CAIQ/custom), send it to infosec@findock.com. We’ll route it to the right experts and respond with the requested level of detail.
Step 4
Engage with our experts
If follow-up questions remain after documentation review, we’ll coordinate a security review call with the appropriate stakeholders.
Security & compliance resources
Access our General Terms and Conditions (EMEA/AMER), DPA, Service Level Standard, VAT info, and other legal resources on our Legal page.
Do you have any questions related to the security at FinDock?
Please contact sales@findock.com








