Security & data handling

Vendor rates, project names and margins are among the most commercially sensitive data a business holds. This page sets out how FinScanix handles them.

Encryption

All traffic runs over HTTPS. Uploaded documents and extracted line-item data are encrypted at rest, and credentials for pricing, payment and model providers are held server-side only — never shipped to the browser.

Role-based access

Owner, Admin, Estimator, Auditor and Viewer roles are enforced on the server for every request. A standard user cannot reach rate management, user administration or billing regardless of what they navigate to.

Tenant isolation

Every query is scoped to the organisation that owns the record. Documents are stored per tenant with no shared bucket paths, so one customer's vendor rates are never reachable from another's session.

Least-privilege integrations

Each external service sits behind a narrow adapter with only the credentials it needs. A pricing key cannot touch billing; a payment key cannot read documents.

Privacy & consent

Personal data is collected only where it is needed to run the service — account identity, the documents you choose to upload, and the audit trail of who did what. Uploaded documents are processed to produce your variance reports and for no other purpose.

Location is used solely to select the correct city cost index and to localise market pricing. It can be set manually per project rather than detected, and the choice is shown on every report.

Retention & deletion

FinScanix retains data linked to an active subscription and to core usage. Deleting a document removes that document, its extracted line items, its cached market quotes and its generated report — and nothing else. Deletion never cascades to other documents or to account data.

On cancellation, exports remain available for a defined wind-down window, after which document artifacts are purged. The exact retention windows and deletion SLA are set in the service agreement.

Complaints & escalation

Any issue with a report, a rate, or the handling of your data can be raised from inside the app or by writing to the support address on your agreement. Complaints are acknowledged and tracked to resolution, and reports can always be regenerated for re-examination because the variance engine is deterministic.

Compliance posture

FinScanix is built to meet applicable government cybersecurity guidance and data-protection obligations in the jurisdictions it operates in. Variance output is advisory decision-support: it is evidence for a commercial conversation, not a legally binding valuation.

Want your data removed? Account owners can delete individual documents from the app at any time, or request full account deletion from Settings. Confirmation is issued once the purge completes.