This Acceptable Use Policy (the “Policy”) governs use of Fintant Inc.’s public website, invitation-only portal, workflow systems, application programming interfaces, files, communications, and related services (collectively, the “Service”).
This Policy is incorporated into the Website and Portal Terms of Use and applies to every user. A signed Client Agreement may impose additional requirements. If this Policy conflicts with a signed Client Agreement, the Client Agreement controls for that conflict.
1. Authorized business use
You may use the Service only:
for legitimate business purposes authorized by the accounting firm or other client organization that invited you; within your assigned organization, role, end-client entity, workflow, account, period, and scope; in accordance with law, professional duties, the Client Agreement, and documented instructions; and through approved devices, accounts, networks, providers, and data-transfer methods.
Portal access is personal and invitation-only. End-client entities are records within an accounting firm’s workspace and do not receive accounts unless Fintant and the accounting firm expressly approve a different arrangement in writing.
2. Accounts, credentials, and devices
You must:
use only your own named account; protect invitations, authentication links or codes, approved recovery methods, sessions, and devices; complete the authentication and recent-authentication checks configured and approved for your account; lock unattended devices and install required security updates; use organization-approved networks and secure remote-access methods; promptly report lost devices, compromised credentials, forwarded invitations, unusual sessions, malware, or unauthorized access; and promptly remove or request removal of access that is no longer needed.
You must not:
share accounts or authentication factors; use generic, group, or another person’s credentials; ask Fintant personnel to bypass identity, authorization, approval, or support-elevation controls; store credentials in notes, messages, spreadsheets, source files, or ordinary email; submit online-banking master, signer, treasury, payment-approval, root, owner, or other excessive credentials; or remain in another user’s session or impersonate a person, organization, or authority.
3. Tenant, data, and instruction authority
You must not access, test, search for, infer, copy, export, disclose, or modify another organization’s records or another end-client entity’s data unless your documented role and scope expressly permit it.
Before submitting information, you must have the authority, notices, consents, contractual permissions, and lawful basis required for Fintant to process it. You must verify that each upload and instruction belongs to the correct:
accounting-firm organization; end-client entity; workflow and work item; account or source; period; authorized service category; and processing country and provider configuration.
You must not use public website forms or public scheduling tools for Client Financial Data, end-client names, tax identifiers, account numbers, credentials, payment-card data, financial statements, source documents, or other sensitive client information.
4. Financial and regulated actions
The Service supports managed accounting production. It does not give users or Fintant independent authority to perform regulated or external financial actions.
You must not use the Service to:
execute, authorize, release, or instruct a payment, transfer, collection, refund, payroll, tax remittance, or other movement of money; file or submit a tax return, regulatory filing, legal filing, or assurance report through Fintant without a separately approved and controlled scope; direct-post to a ledger or accounting system outside the accounting firm’s documented approval workflow; issue legal, tax, investment, audit, review, assurance, or other regulated professional advice under Fintant’s name; communicate with an accounting firm’s end client under Fintant’s own authority; conceal a material difference, unresolved exception, missing source, control failure, or uncertainty; or treat a Fintant-prepared or automated output as final until required Fintant quality assurance and accounting-firm review are complete.
The accounting firm retains responsibility for policies, judgments, approval, posting, filing, payment, and external communication.
5. AI, OCR, and automated systems
You may submit Client Financial Data to an AI, optical character recognition, extraction, classification, or automation service only when that provider, configuration, region, retention mode, security control, workflow, and client authorization are approved.
You must not:
place Client Financial Data in a personal, consumer, public, or unapproved AI account; use Client Financial Data to train a public or general-purpose model; enable provider storage, model-training, plug-in, browsing, sharing, or memory features unless approved; remove source references, confidence, exceptions, model or workflow version, or review evidence; present generated output as professional advice or a guaranteed result; or use generated output for posting, filing, payment, or external communication before required human review.
6. Files and malicious content
You must not upload, distribute, or attempt to process:
malware, ransomware, spyware, malicious macros, executables, scripts, or code intended to run on a user or service system; corrupted, deceptive, polyglot, password-protected, or mislabeled files intended to evade validation or scanning; content that infringes intellectual-property, privacy, confidentiality, or contractual rights; unlawful, fraudulent, threatening, harassing, exploitative, or discriminatory content; or excessive files or payloads intended to disrupt service availability.
A successful transfer does not mean a file is safe or accepted. Fintant may validate file type, calculate hashes, quarantine, scan, reject, restrict, preserve, or remove content. Where production scanning is not active, live Client Financial Data must not be accepted.
7. Privacy and confidentiality
You must minimize personal information and use it only for the approved purpose. You must not:
disclose Client Financial Data, internal notes, security details, service credentials, or confidential information outside authorized channels; copy live data into development, test, demo, analytics, ordinary logs, screenshots, fixtures, support tickets, or unapproved AI systems; place raw financial content, credentials, tax identifiers, account numbers, internal notes, reusable file links, or message bodies in analytics; download or locally store data unless the Client Agreement and approved workflow permit it; send sensitive data through personal email, personal cloud storage, consumer messaging, or public links; access data from an unapproved country, device, contractor environment, or provider; or use client or end-client information for marketing, solicitation, personal benefit, or an unrelated purpose.
8. Platform and system abuse
You must not:
bypass or defeat authentication, authorization, tenant isolation, session expiry, rate limits, file controls, quarantine, audit, approval, retention, deletion, legal-hold, or provider controls; scrape, crawl, enumerate, probe, overload, disrupt, intercept, or interfere with the Service; exploit an error to obtain access, data, service capacity, or economic benefit; create excessive accounts, invitations, jobs, requests, notifications, exports, or downloads; alter request identifiers, organization references, object identifiers, provider events, or audit evidence to misstate authority or result; attempt to recover secrets, source code, keys, credentials, or another party’s confidential information; reverse engineer, decompile, disassemble, copy, or create derivative service technology except to the extent a right cannot legally be restricted; or use the Service to distribute unsolicited communications, deceptive content, phishing, or spam.
9. Security research and vulnerability reporting
Do not perform penetration testing, vulnerability scanning, automated enumeration, credential testing, social engineering, denial-of-service testing, or other security research unless it is within the scope and conditions of Fintant’s published Security Overview and Responsible Disclosure Policy or separately authorized in writing.
If you discover a suspected vulnerability:
stop once you have enough information to demonstrate the issue; do not access, retain, alter, or disclose more data than necessary; do not establish persistence, move laterally, or disrupt service; report it promptly to security@fintant.ai; and keep the issue confidential while Fintant investigates and coordinates remediation.
10. Fraud, sanctions, and unlawful conduct
You must not use the Service to:
commit or facilitate fraud, identity theft, money laundering, bribery, corruption, tax evasion, sanctions evasion, trafficking, or another unlawful act; misrepresent ownership, authority, source, destination, accounting evidence, or transaction purpose; conceal or falsify a source document, approval, exception, audit record, or work status; violate export controls, trade restrictions, sanctions, or anti-money-laundering obligations; or assist another person in prohibited conduct.
Fintant may pause processing and request evidence of authority, source, scope, or lawful purpose.
11. Communications and internal notes
Use client-visible questions, Fintant internal notes, support channels, and notifications only for their intended audience.
You must not:
expose Fintant internal notes to client-facing paths; place credentials, payment instructions, secrets, or unnecessary sensitive data in messages; treat an email or notification as the authoritative approval or work state when the portal provides that state; send abusive, deceptive, discriminatory, or unlawful communications; or use Fintant’s branding or systems to imply approval, certification, or authority that does not exist.
12. Intellectual property, testing, and publicity
You must not:
copy or redistribute Fintant software, interfaces, templates, documentation, or branding except as authorized; remove ownership, confidentiality, watermark, source, control, or version notices; publish confidential benchmarks, penetration-test results, architecture details, or service-performance data without written authorization; use Fintant names, marks, customer relationships, or outputs in publicity without approval; or infringe or misappropriate another party’s intellectual-property rights.
You may provide feedback, but do not include Client Financial Data or another party’s confidential information.
13. Reporting and cooperation
Report suspected misuse, unauthorized access, credential compromise, malware, privacy concerns, or security issues promptly:
Security: security@fintant.ai Privacy: privacy@fintant.ai General support: support@fintant.ai
Do not send credentials or Client Financial Data in ordinary email. Fintant may provide a secure follow-up channel.
You must reasonably cooperate with an authorized investigation, including preserving relevant evidence, revoking exposed access, identifying affected records, and following containment instructions. Do not independently notify an end client, regulator, insurer, law enforcement body, or public audience on Fintant’s behalf.
14. Monitoring and enforcement
To protect the Service and meet legal and contractual duties, Fintant may use proportionate technical and administrative measures to:
validate identity, organization, membership, role, session, request, and file state; maintain audit, security, provider, and operational evidence; investigate suspected misuse; quarantine or restrict content; revoke invitations or sessions; suspend or terminate accounts or workflows; preserve evidence or apply a legal hold; notify the client organization; or disclose information to authorities when required by law.
Where practicable, Fintant will use a proportionate response and allow the client organization to address the issue. Immediate action may be necessary for urgent security, privacy, legal, fraud, sanctions, or safety risk.
15. Questions, exceptions, and changes
Only an authorized Fintant representative may approve a written exception. An accounting-firm administrator cannot approve a Fintant security, provider, country, privacy, or legal exception unless the applicable Client Agreement expressly grants that authority.
Fintant may update this Policy. Material changes will receive notice appropriate to their effect and may require re-acceptance. A policy update does not silently amend a signed Client Agreement.