Security

Security at Steinfin

Steinfin works with sensitive accounts receivable and customer information. Our approach is simple: use only the information the service needs, keep access controlled, and leave you in control of the connection.

Your accounting systemYour records stay here
You authorise the connection, and can revoke it
Only receivables informationInvoices, balances, contacts, payment status
Access limited to your account team
Steinfin workflowFollow-up, promises, queries, history
Actions recorded on the account
Your visibility and controlYou see what happened, and decide the exceptions
What we work with

We only need what the work needs.

Steinfin works mainly with business accounts receivable information and business contact details. That does not make privacy less important: business contacts are still personal data, and we handle client data as a processor under a data processing agreement, in line with GDPR.

What the service uses
  • Invoice details
  • Outstanding balances
  • Payment status
  • Customer business contacts
  • Promises to pay
  • Invoice queries
  • Follow-up history
  • Remittance information
Outside normal scope
  • Payroll
  • HR records
  • Unrelated commercial data
  • Other finance functions
  • Your online banking login
  • Customers' card or bank details
Accounting system access

You authorise the connection. You can remove it.

We work with systems such as Xero, QuickBooks and Sage. The connection is set up from your own account, using the access you grant, and it stays under your control.

  • We never ask you to share your accounting password
  • Access is scoped to reviewing invoices, following up for payment and reporting back to you
  • You can review or revoke the connection at any time
  • Nothing about how you invoice needs to change
Connected appsExample
Steinfin Connected
Authorised by
You, from your account
Used for
Receivables work only
Password shared
Never
DisconnectAvailable to you at any time
Who can see your information

People do see your data. That is the service. So access is limited.

Steinfin is a managed service. Our team needs invoice and customer information to follow up, handle replies and review exceptions. We would rather say that plainly than pretend no one ever sees your data.

  • Access is limited to the people working on your account
  • Your information is not shared outside that team
  • Your information is used only for your account
Steinfin team memberAssigned to your account
Your companyAccess
Another clientNo access
Another clientNo access
Payments

We work with payment information. We never touch the money.

Steinfin's role is accounts receivable operations. We use payment information, such as payment status and remittance details, to keep accounts up to date. The money itself never passes through us.

Payment information
Your recordsSteinfinAccount updated
Used to match payments and keep statuses accurate
Payment funds
Your customerYour bank account
Customers pay you directly, as they do now. Steinfin does not hold client funds.
Systems and providers

How information is handled behind the scenes.

01

Encrypted connections

Our website and its forms are served over HTTPS, and supported accounting platforms connect through their own encrypted connections.

02

AI and automation, with people in charge

Automation and AI can help organise accounts, spot what needs attention and prepare routine work. People review what goes to your customers, and commercial decisions stay with you. Ask us which tools would process your information.

03

Trusted providers, for their job only

We use providers for hosting, email delivery and accounting or workflow software. They may only use data to provide their service to us. Contact us for the current list.

Your customers

Careful communication

We contact your customers only about their own invoices, using the contacts in your records and the rules you agree with us. We do not share one customer's details with another, or disclose more than the follow-up needs.

Retention and offboarding

When you stop using Steinfin

  • 1The accounting connection is disconnected
  • 2Information is kept only as long as our agreement and the law require
  • 3It is then deleted or anonymised

Details are in our privacy policy.

Incidents

If something goes wrong

  1. Identify
  2. Contain
  3. Investigate
  4. Fix
  5. Notify

We notify affected clients and, where required, the relevant authorities. Think you have found a security issue on our website? Email [email protected].

Working together

Security works best as a shared job.

Steinfin
  • Uses only what the work needs
  • Limits access to your account team
  • Handles customer contact carefully
  • Tells you if something goes wrong
You
  • Keep your own logins secure
  • Control who in your team has access
  • Remove access for people who leave
  • Tell us when contacts or access needs change
Security and privacy

Related, but not the same.

SecurityHow information is protected.
PrivacyHow information is collected, used, kept and shared.

Read our privacy policy, website terms and service terms. For how the service runs day to day, see how Steinfin works.

Need more detail?

Send us your security or data questions.

If your team has a questionnaire or specific requirements, send it over. We will answer directly.

Contact Steinfin
Questions

Security, answered.

More about us on the About page.

What information does Steinfin access?

Only what the receivables work needs: invoice details, outstanding balances, payment status, customer business contacts, promises, queries and the history of follow-up on each account. We do not need access to unrelated business information.

Does Steinfin need our accounting password?

No. We never ask you to share your accounting system password. You authorise the connection from your own account, and you can disconnect it at any time.

Can Steinfin see our entire accounting system?

Our access is scoped to what is needed to review invoices, follow up for payment and report back to you. We have no reason to look at unrelated areas such as payroll or HR, and we do not.

Who at Steinfin can access our data?

Only the people working on your account. Because Steinfin is a managed service, those people do see invoice and customer information, since that is how the follow-up gets done. Your information is not shared outside that team.

Does Steinfin hold customer payments?

No. Steinfin does not hold client funds. Your customers keep paying directly into your own bank account or payment system, exactly as they do now.

Does Steinfin store bank credentials?

No. We do not ask for your online banking login, and we never ask your customers for their card or bank details.

Is data encrypted?

Our website and its forms are served over encrypted HTTPS connections, and supported accounting platforms connect through their own encrypted connections. For specific questions about how stored data is protected, contact us and we will answer directly.

Does Steinfin use AI with client data?

Automation and AI can help us organise accounts, spot what needs attention and prepare routine work. People review what goes to your customers, and commercial decisions always stay with you. If you want to know which tools would process your information, ask us before you start.

Is client data used to train AI models?

Ask us about the specific tools involved in your service and we will tell you how each one handles data. We are happy to confirm this in writing as part of onboarding.

Can we revoke access?

Yes. The accounting connection belongs to your account, so you can review or remove it at any time without needing our help.

What happens to our data when we stop using Steinfin?

The accounting connection is disconnected, and your information is kept only as long as our agreement and the law require, then deleted or anonymised. You can also make deletion requests under GDPR.

Which third parties process our data?

We use service providers for things like hosting, email delivery and accounting or workflow software, and they may only use data to provide their service to us. Contact us for the current list.

Does Steinfin have SOC 2 or ISO 27001?

Not at present. Our approach centres on controlled access, minimal data, client-controlled connections and responsible handling. If your procurement process needs specific assurances, contact us and we will answer your questions directly.

What happens if there is a security incident?

We work to identify and contain it, investigate what happened, fix the cause, and notify affected clients and, where required, the relevant authorities.