Executive Summary
AI-generated analysis for Finicity
Finicity (finicity.com) is a financial data and open banking platform — acquired by Mastercard — that has been assigned a Tier 2 (High Risk) rating by ThirdProof's rule engine, reflecting a combination of infrastructure exposure concerns and transparency gaps that warrant heightened due diligence before onboarding. On the positive side, Finicity presents several meaningful trust signals:
Key Findings
- The domain has been registered since 2007, establishing an 18-year operational history.
- All threat intelligence sources return clean results: zero malware, phishing, or abuse reports; no adverse media in either recent or historical archives; and no sanctions matches across OFAC, EU, and UN screening lists.
- The vendor operates a valid TLS 1.3 certificate issued by DigiCert with no weak ciphers, and HSTS is enforced.
- Finicity explicitly commits to not training AI models on customer data, as stated in its published terms and privacy policy at finicity.com/terms-privacy.
- No SEC enforcement filings or FDIC regulatory concerns were identified.
- Finicity's infrastructure resolves through Imperva/Incapsula CDN, which provides meaningful DDoS and application-layer protection. However, several concerns merit attention before this vendor is approved for production use:
- Three sensitive service ports — FTP (21), SMTP (25), and MySQL (3306) — are exposed at the network perimeter. While these appear on a shared CDN edge IP, the exposure warrants formal confirmation that backend services are not directly reachable.
- No public trust center, security page, or SOC 2 claim was found on the vendor's website, which is unusual for a fintech of this scale and creates an audit chain gap for SOC 2 CC9.2 compliance purposes.
- No SOC 2 Type II, ISO 27001, or confirmed HITRUST certification was independently verified; a possible HITRUST directory match exists but requires manual confirmation.
- No subprocessor disclosure page was found, limiting supply chain visibility.
- The marketing site received a C- HTTP security grade, with missing Content-Security-Policy and X-Frame-Options headers. Overall, Finicity's clean threat intelligence posture and operational longevity are positive indicators, but the combination of exposed sensitive ports, absent certification documentation, and lack of supply chain transparency elevates the residual risk profile. A conditional approval with specific remediating requirements is appropriate before this vendor is integrated into production data workflows.
Independence Statement
All evidence in this report was sourced independently by ThirdProof's automated investigation platform without vendor participation, notification, or input.