Third Party Index

Snapshot 57669

Document
Trust center
URL
https://trust.finsweet.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
130395 bytes
SHA-256 (raw)
5c961781885c3dda6f1d508feecd3f36b8afab2b27c7b6083ed6b69b57775ab9
SHA-256 (normalized text)
a081a6922feaaf65aea1b523ea0d66d3dde825f867949872a82bc8432b5ae04d

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Finsweet Inc.
We're a premium Webflow Enterprise Partner, SaaS product builder and community leader.
Trusted by global companies including Dropbox, Vanta and GitHub, we help organizations build, maintain and grow high-performing Webflow websites — extended with our SaaS products for advanced functionality.
Since 2016, Finsweet has been serving a worldwide client base with a remote-first, globally distributed team dedicated to reliability, innovation and security.
security@finsweet.com
Privacy PolicyOpens in new tab
Welcome to the Finsweet Trust Center
Here, you can see our real-time compliance status, explore the live subprocessor list, and request access to security reports and policies. We continuously monitor our systems for security, availability, and privacy, and publish updates directly in the Trust Center.
For a high-level summary of our Information Security Program, visit Finsweet SecurityOpens in new tab. For details on data usage and governance, see our Terms of ServiceOpens in new tab.
Compliance
SOC 2
HIPAA
Resources
View all
SOC 2 reports
SOC 2 Type II — 2024/25
SOC 2 Type II — 2023/24
SOC 2 policies
Information Security Policy
Incident Response Plan
Secure Development Policy
Third-Party Management Policy
View 14 more
HIPAA
HIPAA Compliance Policy
HIPAA Workstation Security Policy
Incident Response Plan HIPAA Addendum with Breach Notification Procedures
Legal
Terms of Service
Opens in new tab
Controls
Updated about 1 hour ago
View all
Infrastructure security
Unique production database authentication enforced
Unique account authentication enforced
Production data segmented
View 12 more Infrastructure security controls
Organizational security
Production inventory maintained
Code of Conduct acknowledged by contractors
Confidentiality Agreement acknowledged by contractors
View 6 more Organizational security controls
Product security
Data encryption utilized
Control self-assessments conducted
Data transmission encrypted
View 3 more Product security controls
Internal security procedures
Continuity and Disaster Recovery plans established
Cybersecurity insurance maintained
Production multi-availability zones established
View 27 more Internal security procedures controls
Data and privacy
Data retention procedures established
Customer data retained
Customer transaction modifications restricted
View 18 more Data and privacy controls
Healthcare data — HIPAA
Application and data criticality analyzed
Contingency operations established
Data backed up and stored
View 54 more Healthcare data — HIPAA controls
Data collected
Customer personally identifiable information
Employee personally identifiable information
Credit card information
Personal health information
Subprocessors
View all
Auth0 • Identity & access management
US, EU
Authentication, user management, and single sign-on (SSO).
Cloudflare • Security & performance
Global
DNS management, security, CDN, serverless functions, and traffic optimization.
Google Cloud Platform • Cloud provider
US, EU
Cloud infrastructure, Firestore database, backups, and Google Auth.
Stripe • Finance and payments
US, EU
Digital payment processing and subscription billing.
FAQ
View all
Updates
View all
Compliance
HIPAA compliance implemented
Published March 21, 2026
March 2026 — Established a HIPAA compliance program to support our growing client baseOpens in new tab in the healthcare sector and customers handling protected health information (PHI), reflecting our continued investment in strengthening security and compliance across our products.
General
Finsweet Trust Center Launched
Published September 12, 2025
September 2025 – A central hub for transparency into our security, privacy, and compliance practices. Customers can now access real-time status, view policies, and track certifications in one place.
Compliance
Second SOC 2 Type II audit completed
Published September 12, 2025
May 2025 — Expanded scope to cover all paid products: CMS BridgeOpens in new tab, Consent ProOpens in new tab, Finsweet AccountsOpens in new tab, Finsweet ComponentsOpens in new tab, and WizedOpens in new tab. This milestone reflects our commitment to strengthening security as our ecosystem grows.
Compliance
First SOC 2 Type II audit completed
Published September 12, 2025
June 2024 — Covered WizedOpens in new tab and Finsweet AccountsOpens in new tab. SOC 2 compliance was initiated to meet the needs of Wized customers and marked the start of our ongoing investment in enterprise-grade security and compliance.