Skip to content
Trust center

Security built into the AP payment flow.

Finexio protects supplier payments with verification, bank-account validation, screening, payment monitoring, SOC 2 Type II reviewed controls for in-scope systems, J.P. Morgan payment infrastructure for supported workflows, and Finexio Shield coverage for eligible covered payments.

SOC 2 request path

Request SOC 2 evidence in four steps.

Finexio does not publish sensitive security artifacts as open web collateral. The review path gives qualified teams the right materials for the systems, workflows, and payment program being evaluated.

  1. 01

    Start with Finexio sales

    Share buyer, partner, program, and diligence context with sales so Finexio can qualify the request and route the right materials.

    Sales qualification and routing

  2. 02

    Confirm scope and access

    The SOC 2 Type II report (Schellman & Company, LLC; Security; April 1, 2025 to March 31, 2026) and supporting security materials are provided as appropriate, often under NDA.

    Scoped materials

  3. 03

    Map controls to workflow

    Finance, IT, security, and legal teams can review how controls apply to the intended payment program.

    Control walkthrough

  4. 04

    Close implementation questions

    Data flow, file handling, supplier operations, status reporting, and escalation paths are resolved before launch.

    Launch readiness

Control matrix

Controls attach to payment release gates.

Buyers can review how controls attach to supplier setup, payment detail changes, release decisions, exception handling, and covered payment review. Final applicability depends on program scope and agreement terms.

Control surface

Supplier identity and payee changes

Supplier details, ownership signals, payment preferences, and bank-account changes are reviewed before release.

Evidence buyers can review

Verification workflow and operations review

Where it applies

Before payment release

Bank-account validation

Bank-account changes are treated as high-risk events and routed through validation workflows before money moves.

Evidence buyers can review

Account-change controls

Where it applies

At setup and change events

Payee screening

Finexio supports KYC, OFAC, AML, and payee-risk review through screening and managed operations.

Evidence buyers can review

Screening and risk review

Where it applies

Before supported disbursement

Payment monitoring

Transactions are reviewed for unusual or risky behavior before release, when funds can still be protected.

Evidence buyers can review

Exception handling and review queues

Where it applies

Pre-release and exception states

Audited control environment

Finexio's SOC 2 Type II examination was performed by Schellman & Company, LLC, covering controls relevant to Security for the period April 1, 2025 to March 31, 2026. The full report can be provided to qualified buyers and partners during sales-led diligence, subject to scope and access requirements.

Evidence buyers can review

SOC 2 Type II diligence path

Where it applies

For in-scope systems

Covered-payment response

Finexio Shield is a paid program that provides a $2M guarantee on covered payments. It is governed by its own program terms, eligibility, exclusions, and the applicable customer agreement.

Evidence buyers can review

Shield eligibility and program terms

Where it applies

After eligible covered issue review

Technical controls

The controls behind the trust center.

These are the technical and operational controls Finexio runs across in-scope systems and the payment workflow. Scope and applicability are confirmed during diligence.

Encryption

Customer and payment data is encrypted in transit and at rest.

Access controls

Access to in-scope systems is role-based, limited to what each role needs, and reviewed.

Vulnerability management

Continuous scanning identifies issues, and remediation is tracked to closure.

Annual penetration testing

Independent penetration tests run annually against in-scope systems.

Annual SOC 2 Type II examination

Performed by Schellman & Company, LLC, covering controls relevant to Security for the period April 1, 2025 to March 31, 2026.

Payment-release controls

The release-gate controls on supplier identity, bank-account changes, payee risk, and transaction review live in the control matrix above.

SOC 2 Type II (Schellman)J.P. Morgan issuing bankVisa network$2M Finexio Shield on covered payments
Payment-control diagram

Controls follow the payment from approved file to reconciliation.

The workflow is built for AP teams that need a clean handoff: buyer-approved payments in, managed payment delivery out, with control checks before release and operations support after.

  1. Step 1

    Buyer AP approval

    Approved invoices or payment file leave the buyer-controlled workflow.

    • Buyer approval remains upstream
    • Program and file scope confirmed
  2. Step 2

    Finexio intake

    Payment data is received for orchestration, validation, routing, and status handling.

    • File handling review
    • Implementation data-flow mapping
  3. Step 3

    Supplier checks

    Payee, payment preference, bank-account, and risk signals are reviewed before release.

    • Release gates from the control matrix
  4. Step 4

    Payment release

    Supported payment workflows are routed across the appropriate rail and infrastructure.

    • Monitoring before release
    • J.P. Morgan infrastructure where supported
  5. Step 5

    Exceptions and reporting

    Returns, reissues, statuses, remittance, and reconciliation are managed back to the buyer.

    • Operations escalation
    • Reconciliation support

J.P. Morgan is the issuing bank behind card payments and provides payment infrastructure for supported workflows. Finexio is the orchestration platform that runs the operation, not a bank, and payment methods depend on program structure.

Finexio Shield

What Shield covers.

Finexio Shield is a paid program that provides a $2M guarantee on covered payments. It is governed by its own program terms, eligibility, exclusions, and the applicable customer agreement. Buyers should review coverage terms, exclusions, eligibility, operating procedures, and contractual requirements during diligence.

1

Control first

Shield is designed around pre-release controls such as supplier verification, bank-account review, screening, and payment monitoring.

2

Eligibility review

Coverage applies only to eligible covered payments and depends on program terms, exclusions, customer agreement, and operating procedures.

3

Response path

If a covered issue is raised, Finexio reviews the payment record, control path, and program terms before any coverage determination.

Vulnerability disclosure

Route vulnerability reports separately from diligence requests.

Prospective security questionnaires, SOC 2 access, and data-flow reviews begin with Finexio sales. Potential vulnerabilities should use the support ticket path so the report is not treated like a sales or demo request.

Use the support ticket path

Submit potential vulnerability reports through the Finexio support ticket path. Include enough context to reproduce the issue, but avoid sending sensitive account, supplier, or bank details in the first message.

Separate reports from diligence

Prospective SOC 2 requests, questionnaires, and data-flow reviews begin with sales. Potential vulnerabilities should use the support ticket path.

Preserve evidence carefully

Include affected host, endpoint, steps, timestamps, screenshots where appropriate, and your preferred contact method. Do not test against production payment data.

Security review checklist

Prepare the diligence conversation before requesting artifacts.

Use this checklist to align finance, IT, security, legal, and implementation stakeholders before qualified diligence begins. It is built from the same control surfaces and request items used across this trust center.

Program context

  • Confirm buyer, partner, program, and diligence owner context.
  • Define AP payment scope, supported workflows, and intended payment rails.
  • Identify customer systems, file transfer approach, and implementation timeline.

Evidence request

  • Coordinate SOC 2 Type II scope and period through sales-led diligence.
  • Prepare security questionnaire, data-flow, and implementation review questions.
  • Confirm whether NDA, customer-specific access, or scope restrictions apply.

Payment controls

  • Review supplier identity, bank-account validation, payee screening, and monitoring controls.
  • Map controls to payment intake, release, exception handling, and reconciliation.
  • Review Finexio Shield eligibility, exclusions, operating procedures, and agreement terms.

Copy-ready checklist

Program context
- Confirm buyer, partner, program, and diligence owner context.
- Define AP payment scope, supported workflows, and intended payment rails.
- Identify customer systems, file transfer approach, and implementation timeline.

Evidence request
- Coordinate SOC 2 Type II scope and period through sales-led diligence.
- Prepare security questionnaire, data-flow, and implementation review questions.
- Confirm whether NDA, customer-specific access, or scope restrictions apply.

Payment controls
- Review supplier identity, bank-account validation, payee screening, and monitoring controls.
- Map controls to payment intake, release, exception handling, and reconciliation.
- Review Finexio Shield eligibility, exclusions, operating procedures, and agreement terms.
Diligence packet

Bring finance, IT, security, and legal into one review.

A sales-led diligence conversation can cover control evidence, payment workflow review, supplier support, infrastructure qualifiers, and Shield questions in one place.

What the review can include

  • SOC 2 Type II review path
  • Security questionnaire support
  • Payment-control overview
  • Implementation and data-flow review
  • Finexio Shield eligibility discussion
  • Supplier support and escalation model
  • Vulnerability support-ticket routing

Availability of specific documents and walkthroughs depends on customer context, program scope, NDA status, and the systems or workflows being reviewed.

Trust request workflow

Eligible requesters

Prospective buyers and partners begin with Finexio sales when a real program evaluation is underway. Existing customers use a support ticket for account-specific needs.

Access and NDA

SOC 2 materials, questionnaires, DPA requests, and customer-specific artifacts may require NDA, scope confirmation, and named review owners.

Artifact menu

Common requests include SOC 2 review, security questionnaires, data-flow review, payment-control walkthroughs, supplier-support model, and Shield eligibility discussion.

Escalation paths

Prospective diligence begins with sales. Vulnerability reports, suspicious payment-change activity, incidents, and account-specific questions use the support ticket path.

Security FAQ

Common diligence questions.

How does a SOC 2 review work?+

Finexio's SOC 2 Type II examination was performed by Schellman & Company, LLC, covering controls relevant to Security for the period April 1, 2025 to March 31, 2026. Prospective buyers and partners begin with Finexio sales; report access and any NDA requirements are handled during qualified diligence.

What security evidence can Finexio provide?+

Finexio can support security questionnaires, SOC 2 Type II review, payment-control walkthroughs, implementation data-flow review, supplier-support diligence, and Finexio Shield eligibility discussion.

Where should vulnerability reports go?+

Potential vulnerability reports should use the Finexio support ticket path. Prospective security diligence begins with Finexio sales.

Is Finexio a bank?+

J.P. Morgan is the issuing bank behind card payments and provides payment infrastructure for supported workflows. Finexio is the orchestration platform that runs the operation, not a bank, and payment methods depend on program structure.

Where do payment controls sit?+

Controls are applied in the payment workflow between buyer-approved payment intake and payment release, including supplier verification, bank-account validation, payee screening, monitoring, exception handling, and reconciliation support.

What does Finexio Shield cover?+

Finexio Shield is a paid program that provides a $2M guarantee on covered payments. It is governed by its own program terms, eligibility, exclusions, and the applicable customer agreement. Buyers should review coverage details during security and legal diligence.

Do all programs use the same rails and controls?+

No. Security, compliance, supported payment methods, payment infrastructure, coverage, and implementation details depend on program scope, payment eligibility, supplier data, and agreement terms.

Important qualifiers

Security, compliance, payment coverage, and implementation details depend on program scope, contractual terms, payment eligibility, customer data, and approved operating procedures. Finexio confirms the applicable controls and coverage during diligence.