Security of Third-Party Integrations: Finch
overview finch is a subcontracted service provider used by charthop to deliver certain hr and payroll integrations we perform due diligence and ongoing security reviews of finch as part of our vendor management program while each organization's procurement and security requirements differ, many customers rely on our vendor assessment process rather than conducting a separate review of finch if your internal policies require direct review of subprocessors or third party service providers, we're happy to discuss finch's role and provide available documentation finch's role in the integration finch operates as a unified api that connects to hr and payroll systems on behalf of the integration when an integration is powered by finch, employer and employee data flows through finch's infrastructure as part of delivering the connection finch's security and compliance posture finch maintains a third party audited security program its publicly attested compliance frameworks include (as of jun 1, 2026) framework status soc 2 type ii audited annually by a certified third party hipaa compliant gdpr compliant ccpa compliant eu u s / swiss u s data privacy framework (dpf) self certified finch's program covers the areas customers most often assess, including access controls and encryption, vulnerability management with regular third party penetration testing, incident response, vendor risk management, availability and business continuity, and change management accessing finch's documentation detailed documentation (nda required) finch's detailed security materials are available through finch's trust center under nda to request access, please submit a request directly at the trust center so the nda can be processed with your organization https //finch secureframetrust com https //finch secureframetrust com general overview (no nda required) for a high level overview of finch's security program that is not gated, see finch's security whitepaper https //www tryfinch com/resources/whitepapers/security https //www tryfinch com/resources/whitepapers/security how to proceed if your security or procurement team requires a direct review of finch as a subprocessor, we recommend requesting the gated documentation through finch's trust center so the nda can be handled directly between your organization and finch for a general understanding of finch's posture, the security whitepaper above is the best starting point reach out to your charthop contact with any questions about finch's role in your integration
