Skip to content
Finero
Security and compliance

The safest data is the data we never hold.

Finero sits between your ERP and your payment provider, handling invoices, customer records and payment flows. The most important thing to understand about how it is built is what it deliberately never touches: your customers’ card numbers, and your money.

No cardholder data

Finero does not store cardholder data, primary account numbers, CVVs or full track data. There is no card vault to breach because there are no cards in it.

Funds never held

Money settles directly to your merchant account on your existing payout schedule. Finero never takes custody of customer funds.

GDPR-aligned privacy

Personal data is minimised, processed only for defined purposes, and retained according to documented policies.

Full audit trail

Every collector action, payment event and ERP write-back is logged with actor, timestamp and payload diff.

No change to your PCI scope

Finero uses provider-hosted payment pages, so it does not bring additional systems into PCI scope. You keep your existing merchant agreement, payment provider relationship, and current compliance position.

Your ERP stays the system of record

Invoices and customer records flow into Finero so it can chase and match them. Payments and reconciliation entries flow back. The direction of authority never changes: your ERP remains the ledger of truth, and Finero is an operational layer on top of it rather than a replacement for it. If Finero were removed tomorrow, your ledger would still be correct and complete.

Every write-back is logged with the actor, a timestamp and a payload diff, so any entry Finero posted can be traced to the action that caused it. That matters for internal controls, and it matters in a dispute, where a documented contact and payment history is the evidence that reasonable steps were taken.

Security review and documentation

If your security team runs a formal vendor review, raise it during your demo and we will route the questionnaire to the person who can answer it properly. For how personal data is handled, see the privacy policy.

Security questions

Does Finero store our customers' card details?

No. Finero does not store cardholder data, primary account numbers, CVVs or full track data.

Does Finero hold our money?

No. Funds settle directly into your own merchant account on your existing payout schedule. Finero never takes custody of your cash, which means there is no float, no commingling of funds, and no dependency on Finero's solvency for you to be paid.

How does using Finero affect our PCI DSS scope?

Finero uses provider-hosted payment pages, so it does not bring additional systems into PCI scope. You keep your existing merchant agreement, payment provider relationship, and current compliance position.

What does Finero read from and write to our ERP?

Invoices and customer records flow into Finero so it can chase and match them. Payments and reconciliation entries flow back so your ERP stays the system of record. Your ERP remains the ledger of truth; Finero does not replace it.

Can we see who did what?

Yes. Every collector action, payment event and ERP write-back is logged with the actor, a timestamp and a payload diff, so any change can be traced to the person or process that made it.

Can we get security documentation for our review process?

Yes. Ask during your demo and we will route your security questionnaire to the right person rather than sending a generic pack.

Bring your security team to the demo.

Book a 30-minute demo with a Finero expert. See how Finero chases, collects, and reconciles invoices end-to-end.