Encryption everywhere
Data is encrypted in transit (TLS 1.3) and at rest, with field-level encryption for the most sensitive fields, including PHI.
Receivables carry sensitive — and often protected — information. CollFin treats it that way, with encryption, isolation, and access controls applied by default.
Data is encrypted in transit (TLS 1.3) and at rest, with field-level encryption for the most sensitive fields, including PHI.
Row-level isolation keeps every client's receivables, consumer data, and payments separate — even on shared infrastructure.
Access is scoped to what each role needs, and every read and change is captured in a tamper-evident audit trail.
Card payments run through a PCI-compliant hosted processor. We never store full card numbers.
We sign BAAs and apply minimum-necessary handling for healthcare data. More on HIPAA →
Found a vulnerability? We want to hear from you — contact our team for responsible disclosure.