Security of Third-Party Integrations: Finch
Overview
Finch is a subcontracted service provider used by ChartHop to deliver certain HR and payroll integrations. We perform due diligence and ongoing security reviews of Finch as part of our vendor management program. While each organization's procurement and security requirements differ, many customers rely on our vendor assessment process rather than conducting a separate review of Finch.
If your internal policies require direct review of subprocessors or third-party service providers, we're happy to discuss Finch's role and provide available documentation.
Finch's role in the integration
Finch operates as a unified API that connects to HR and payroll systems on behalf of the integration. When an integration is powered by Finch, employer and employee data flows through Finch's infrastructure as part of delivering the connection.
Finch's security and compliance posture
Finch maintains a third-party-audited security program. Its publicly attested compliance frameworks include (as of Jun 1, 2026):
Framework | Status |
|---|---|
SOC 2 Type II | Audited annually by a certified third party |
HIPAA | Compliant |
GDPR | Compliant |
CCPA | Compliant |
EU-U.S. / Swiss-U.S. Data Privacy Framework (DPF) | Self-certified |
Finch's program covers the areas customers most often assess, including access controls and encryption, vulnerability management with regular third-party penetration testing, incident response, vendor risk management, availability and business continuity, and change management.
Accessing Finch's documentation
Detailed documentation (NDA required)
Finch's detailed security materials are available through Finch's Trust Center under NDA. To request access, please submit a request directly at the Trust Center so the NDA can be processed with your organization:
General overview (no NDA required)
For a high-level overview of Finch's security program that is not gated, see Finch's security whitepaper:
How to proceed: If your security or procurement team requires a direct review of Finch as a subprocessor, we recommend requesting the gated documentation through Finch's Trust Center so the NDA can be handled directly between your organization and Finch. For a general understanding of Finch's posture, the security whitepaper above is the best starting point. Reach out to your ChartHop contact with any questions about Finch's role in your integration.
