How does a SOC 2 review work?+
Finexio's SOC 2 Type II examination was performed by Schellman & Company, LLC, covering controls relevant to Security for the period April 1, 2025 to March 31, 2026. Prospective buyers and partners begin with Finexio sales; report access and any NDA requirements are handled during qualified diligence.
What security evidence can Finexio provide?+
Finexio can support security questionnaires, SOC 2 Type II review, payment-control walkthroughs, implementation data-flow review, supplier-support diligence, and Finexio Shield eligibility discussion.
Where should vulnerability reports go?+
Potential vulnerability reports should use the Finexio support ticket path. Prospective security diligence begins with Finexio sales.
Is Finexio a bank?+
J.P. Morgan is the issuing bank behind card payments and provides payment infrastructure for supported workflows. Finexio is the orchestration platform that runs the operation, not a bank, and payment methods depend on program structure.
Where do payment controls sit?+
Controls are applied in the payment workflow between buyer-approved payment intake and payment release, including supplier verification, bank-account validation, payee screening, monitoring, exception handling, and reconciliation support.
What does Finexio Shield cover?+
Finexio Shield is a paid program that provides a $2M guarantee on covered payments. It is governed by its own program terms, eligibility, exclusions, and the applicable customer agreement. Buyers should review coverage details during security and legal diligence.
Do all programs use the same rails and controls?+
No. Security, compliance, supported payment methods, payment infrastructure, coverage, and implementation details depend on program scope, payment eligibility, supplier data, and agreement terms.