FINNY announces Pay As You Grow model to support advisor growth →
For compliance & supervisory teams

Built for advisor and compliance peace of mind.

Advisors trust FINNY to bring next-gen prospecting into their daily workflows — and rely on us to fit cleanly inside the regulatory framework their firms operate under. Our platform and product are designed for the rigorous standards of the financial-advisory industry.

Platform security

Engineered for security. Audited for trust.

FINNY's platform is independently audited, encrypted in transit and at rest, and operated from the United States. The detailed reports — SOC 2 Type II, data handling overview, subprocessor list — are in the compliance packet.

SOC 2 Type II
Independently audited security controls. Audit period August–October 2025.
Defense in depth
Encryption at rest and in transit, role-based access controls, and OAuth-scoped email integration. FINNY never stores user credentials.
US data residency
FINNY runs securely on AWS — all data is stored and processed in the United States.
Pen tested annually
Independent third-party penetration testing of FINNY's platform and infrastructure, with documented remediation tracking.

Independently audited

SOC 2 Type II audit completed for security, covering August–October 2025. Platform and infrastructure are also penetration tested by independent third parties.

Engineered for security

Data encrypted in transit and at rest. Role-based access controls across the application and infrastructure. Enterprise SSO available for firms that require centralized identity management.

Continuously monitored

Continuous security monitoring through Datadog SIEM. Automated alerting on suspicious activity, with documented incident response procedures.

US-based operations

FINNY's production infrastructure runs on AWS. All data is stored and processed in the United States.

Prospecting compliance

Designed to fit the regulatory frameworks that govern advisor outreach.

Advisors are subject to FINRA Rule 2210, the SEC Marketing Rule, CAN-SPAM, TCPA, and Reg S-P / GLBA depending on their firm structure. FINNY's drafting-and-approval workflow, delivery through the advisor's own email, and prospecting-only data model are designed to fit cleanly inside each of these frameworks. FINNY does not provide legal or compliance advice; each firm sets its own supervisory procedures.

FINRA Rule 2210

Communication with the public

For advisors affiliated with a broker-dealer. FINNY supports the substance of compliant outreach.

  • Pre-use review and advisor approval on every message
  • Fair-and-balanced content; FINNY's drafting avoids performance predictions
  • Advisors can include required disclosures, BrokerCheck references, and firm attribution
SEC Marketing Rule (206(4)-1)

Advertisements by RIAs

FINNY drafts only suggestions; the advisor controls all content before sending.

  • Full advisor edit and approval before sending
  • FINNY's drafting avoids testimonials, performance projections, and unverified claims
  • Advisors can include required disclosures in every message before sending
CAN-SPAM

Commercial email

Every email FINNY sends is personalized to its individual recipient.

  • Sent through the advisor's authorized channel — accurate sender information
  • Opt-out tracking and suppression management
  • Timestamped recordkeeping for review
TCPA

Voicemail & phone outreach

FINNY does not auto-dial. Voicemail drops are advisor-initiated and tracked.

  • Phone numbers on the federal DNC list are flagged via licensed data
  • Prospect location (when available) to support calling-window decisions
  • Notes field available to capture consent basis or call rationale
  • Centralized records for supervisory review
Reg S-P & GLBA

Customer data privacy

FINNY is a prospecting-only platform. Customer non-public information is not required by the platform.

  • No customer NPI ingested by default
  • Prospect data from public and licensed providers
  • No data resale, rental, or sharing with third parties for marketing or advertising
  • DPA available on request to reflect specific firm requirements
Books & Records

Recordkeeping & archiving

FINNY logs activity for supervisory review. Outreach flows through the advisor's authorized channels, supporting firms' monitoring, auditing, and archiving requirements.

  • Timestamped activity logs for all outreach
  • Email delivered through the advisor's connected email account
  • Activity captured across email, voicemail, personalized messaging, and phone outreach

FAQ

Common compliance questions.

Pulled from actual conversations with the supervisory and CCO teams we work with.

Our firm is subject to FINRA rules. Does Rule 2210 apply to outreach through FINNY?

If your firm is a FINRA-member broker-dealer, then yes — Rule 2210 applies to advisor outreach sent through FINNY. The rule is triggered by the content of the message, not by FINNY itself. FINNY is designed to support fair and balanced communications, but firms should set their own review and approval procedures.

Is FINNY considered “cold outreach”?

FINNY facilitates personalized, research-based outreach to prospects who fit an advisor's target profile. Whether a message qualifies as “cold outreach” depends on prior relationships, consent, and on each firm's policy. Advisors should confirm with their compliance teams how FINNY may be used under their specific regulatory framework.

Who owns the communications records generated through FINNY?

Your firm does. Every message sent through FINNY is your firm's communication, and your firm owns it, along with the prospect data, notes, and content you put into the platform. That follows from how the platform is built. FINNY drafts and stages outreach, but your firm reviews and approves every client-facing message before it goes out, and messages are sent from your own email domain in your firm's name, brand, and voice. Your firm is the author of the communication. Because outreach flows through your existing domain, it is captured automatically by your existing archiving and supervision infrastructure. Records subject to Advisers Act Rule 204-2, or to Exchange Act Rules 17a-3 and 17a-4 and FINRA Rule 4511, are retained through the existing systems. There is no parallel record set to reconcile and no dependency on FINNY to satisfy your retention obligations. FINNY separately logs platform activity (what was drafted, who approved it, and when it was sent) and makes those logs available to your firm through authorized channels for supervisory review. FINNY does not send communications in its own name and is not the system of record for your firm's books and records.

How does FINNY comply with Regulation S-P and GLBA?

FINNY is designed for prospecting and works with publicly available information and data from licensed providers. Customer non-public information is not required by the platform. Firms should still ensure that any integration of FINNY with their own systems complies with their information security policies.

What happens if a prospect complains about being contacted?

Advisors are responsible for responding to prospect complaints in accordance with their firm policies. FINNY can provide records of communication activity to support the advisor's response, and includes tools to flag prospects for no further contact.

How do we get the SOC 2 report and other compliance documents?

Request the compliance packet from this page — share your name, firm, and email and our team will send it over. It includes the SOC 2 Type II report, the due diligence questionnaire, the data handling overview, regulatory framework alignment, and insurance detail. If your firm has additional requirements — a Data Processing Addendum, vendor security questionnaire, or anything else — let us know in the same request and we'll get back to you directly.

Is FINNY itself a registered investment adviser?

No. FINNY is a technology and marketing-automation provider. We build the software and data that help your firm identify, prioritize, and reach prospects. We do not provide investment advice. FINNY exercises no investment discretion, holds no client funds or securities, maintains no client accounts, and manages no assets. We make no recommendation to any investor about the value of a security or the advisability of buying, holding, or selling one, and we do not hold ourselves out to the public as providing investment advice. Any prioritization the platform produces is a recommendation to your firm about which prospects to contact, not advice to an investor about securities. FINNY does not meet the definition of an investment adviser under the Investment Advisers Act of 1940 and is not required to register with the SEC. Under the Securities Exchange Act of 1934, FINNY is not a broker-dealer and is not required to register as one or to become a FINRA member.

Is FINNY a solicitor or promoter under the SEC Marketing Rule?

No, FINNY is not a compensated promoter. Outreach sent through FINNY is authored, reviewed, approved, and transmitted by your firm, in your firm's name, brand, and voice, through your firm's email domain. There is no separate FINNY statement approving, endorsing, or recommending your firm to a prospect, and an endorsement under the Marketing Rule requires a statement by someone other than the adviser. FINNY supplies data and software; your firm supplies the message and the judgment.

Do we need to update our Form ADV?

Use of FINNY is not expected to trigger new Form ADV disclosure obligations, including with respect to the fee mechanics. FINNY is not a compensated promoter, so the Marketing Rule's promoter disclosure requirements are not triggered, and FINNY's fee is a firm expense paid by your firm, not a charge to your clients. That said, your Form ADV is your firm's filing. Confirm with your own CCO or counsel.

Do our clients need to be told that FINNY is paid?

No client-facing disclosure is required. The Marketing Rule's promoter disclosure requirements exist so clients know when a third party has a financial stake in recommending an adviser. Because FINNY does not recommend or endorse your firm to prospects, those requirements are not triggered. FINNY's fee is paid by your firm out of firm revenue and is not deducted from, or charged to, any client account.

Is FINNY's fee transaction-based compensation?

No. FINNY's fee is asset-based, not transaction-based. FINNY does not solicit investors in securities transactions, make recommendations, structure transactions, or handle customer funds or securities. FINNY is not a broker-dealer and is not required to register with the SEC or become a FINRA member.

Have a question your CCO needs answered?

We work directly with compliance teams during onboarding. If something isn't covered in the packet, send it our way.

Important disclaimer

FINNY is a technology platform designed to support advisor prospecting and communication workflows. FINNY does not provide legal or compliance advice. Advisors and their supervising firms remain responsible for ensuring that their use of FINNY complies with all applicable laws, regulations, and firm policies.

This page is for informational purposes only and is not intended as legal or compliance guidance. Regulatory requirements may vary across firms and may change over time. FINNY's features and capabilities are continually evolving. For the most current information, please contact the FINNY team.