Our approach
Security is considered throughout the design, development and operation of Finbl. We aim to apply proportionate technical and organisational controls based on the information, systems and risks involved.
Trust
An overview of how Finbl approaches security and how to report a potential vulnerability.
Last updated: 18 June 2026
Security is considered throughout the design, development and operation of Finbl. We aim to apply proportionate technical and organisational controls based on the information, systems and risks involved.
Our security programme may include controls such as:
This list is a general description rather than a guarantee that every control applies identically to every service or implementation.
Security is shared. Customers should manage authorised users, permissions, devices, credentials, integrations and internal processes appropriately. Specific responsibilities will be set out in customer agreements and implementation documentation.
If you believe you have found a security vulnerability, report it privately to privacy@finbl.co.uk. Include enough detail for us to understand and reproduce the issue.
Please do not access, alter, download or disclose data that does not belong to you, disrupt services, use automated high-volume testing or publicly disclose an issue before we have had a reasonable opportunity to investigate it.
We aim to acknowledge genuine reports promptly, investigate them proportionately and keep the reporter informed where appropriate. Response targets and any formal safe-harbour statement should be added once an internal vulnerability disclosure process is approved.
Prospective and existing customers may request further information about Finbl’s security arrangements, subject to appropriate confidentiality and the sensitivity of the information requested. Contact privacy@finbl.co.uk.
Have a question?
Contact us about this policy.