Compliance & Trust

Security built for regulated data.

Receivables carry sensitive — and often protected — information. CollFin treats it that way, with encryption, isolation, and access controls applied by default.

Encryption everywhere

Data is encrypted in transit (TLS 1.3) and at rest, with field-level encryption for the most sensitive fields, including PHI.

Tenant isolation

Row-level isolation keeps every client's receivables, consumer data, and payments separate — even on shared infrastructure.

Least-privilege access

Access is scoped to what each role needs, and every read and change is captured in a tamper-evident audit trail.

Payments off-limits

Card payments run through a PCI-compliant hosted processor. We never store full card numbers.

HIPAA-ready

We sign BAAs and apply minimum-necessary handling for healthcare data. More on HIPAA →

Report an issue

Found a vulnerability? We want to hear from you — contact our team for responsible disclosure.

Security and compliance go together.