Security Overview
Last updated: 13 January 2026
Farben.ai is an AI-powered finance automation platform operated by the TechFarben Group. This Security Overview describes the security controls and operational practices we maintain to protect customer data processed in the Farben.ai platform.
This page is intended to support vendor security reviews and procurement due diligence. For contract-level obligations, please refer to your Master Services Agreement and Data Processing Addendum (DPA).
1. Our Security Principles
- Confidentiality, integrity, availability: Protect customer data against unauthorised access, alteration, or loss.
- Least privilege: Access is limited to what is necessary.
- Defence in depth: Multiple layers of security controls.
- Auditability: Maintain logs and evidence for investigations and compliance.
- Secure by design: Security considered throughout development and operations.
2. Data Protection and Ownership
- Customer data remains Customer's data. Farben.ai processes customer data only on customer instructions as set out in the Agreement and DPA.
- No sale of personal data.
- AI training stance (default): Customer data processed in the platform is not used to train public or third-party AI models.
3. Access Controls
- Role-Based Access Control (RBAC): Roles and permissions are used to limit access.
- Least privilege: Access is granted only to authorised users and personnel who need it.
- Authentication: Secure authentication mechanisms are used for user access (including support for MFA where configured/available).
- Administrative access: Restricted to a limited set of authorised personnel.
4. Encryption
- In transit: Data is protected using industry-standard transport encryption (e.g., TLS).
- At rest: Platform data is encrypted at rest where supported by the underlying infrastructure and services.
5. Infrastructure and Hosting
- Farben.ai runs on secure cloud infrastructure with standard cloud security controls.
- Environments are segregated (e.g., production vs non-production) with controlled access.
- System components are configured to reduce exposure and limit attack surface.
6. Application Security and Secure Development
- Secure SDLC: Security practices are integrated into development and release processes.
- Change management: Controlled deployments with review and rollback procedures.
- Secrets management: Credentials and sensitive configuration values are handled using secure methods and restricted access.
- Dependency hygiene: We aim to keep dependencies updated and address identified security issues.
7. Vulnerability Management
Monitoring and remediation: We track vulnerabilities and apply patches based on risk and severity.
Testing: We may use automated scanning and security checks as part of development and operations.
If you wish to report a vulnerability, please contact support@techfarben.com.
8. Logging, Monitoring, and Audit Trails
- Operational logging: Platform events and system activity are logged for troubleshooting and investigation.
- Audit trails: User actions and workflow activity can be captured to support finance controls and governance.
- Alerting: Monitoring and alerting help detect abnormal behaviour and service issues.
9. Incident Response
We maintain incident response procedures designed to detect, respond to, and recover from security incidents.
Breach notification: Where a personal data breach affects customer data processed as a processor, we notify the customer without undue delay in accordance with our DPA and applicable law.
10. Business Continuity and Disaster Recovery
- Backups: We maintain backup and recovery practices to support business continuity.
- Resilience: We implement operational measures intended to reduce downtime and recover service.
- Specific recovery objectives (RPO/RTO) may be agreed contractually for enterprise plans.
11. Data Retention and Deletion
- Customer-configured retention: Where available, customers can define retention and access policies.
- Termination: Data export and deletion are handled in line with the Agreement and DPA, subject to legal retention and backup cycles.
12. Subprocessors
We may use vetted subprocessors for hosting, monitoring, and service delivery. Subprocessors are bound by contractual confidentiality and data protection obligations. A current list is available upon request at support@techfarben.com.
13. AI Security and Human-in-the-Loop Controls
- Farben.ai uses AI agents to assist with document extraction, classification, reconciliation support, and exception detection.
- AI outputs are assistive and may contain errors.
- The platform supports human review and approval workflows.
- Access to documents, prompts, and outputs is controlled through roles and permissions.
14. Customer Responsibilities (Shared Security Model)
Customers play a key role in security. We recommend customers:
- enforce strong passwords and enable MFA where possible
- maintain appropriate user access reviews and segregation of duties
- apply least-privilege permissions and promptly remove leavers
- ensure secure configuration of integrations and API credentials
- avoid uploading special-category or highly sensitive personal data unless explicitly agreed
15. Compliance and Procurement Support
We can support procurement teams with:
- security questionnaires
- architecture summaries
- data flow explanations
- DPA/SCC/transfer documentation
For enterprise procurement requests, email support@techfarben.com.
16. Contact
TechFarben Group entities (contracting entity as per Order Form):
- TECHFARBEN LIMITED (UK) — 71–75 Shelton Street, Covent Garden, London, England, WC2H 9JQ.
- TECHFARBEN PTE. LTD. (Singapore) — 122 McNair Road, #02-49, Singapore 320122.
- TechFarben India Pvt Ltd (India) — Cyber City, DLF Phase 2, Sector 25, Gurugram, Haryana 122001, India.