Security questions and answers
The questions customers and procurement teams ask most, answered directly.
Reflects how Cadence works today. Covers Cadence Fi Ltd, trading as CadenceFi.
Data and hosting
- Where is customer data stored?Yes
- Financial data is stored in the UK.
- Is one customer's data kept separate from another's?Yes
- Yes. Each company's data is separated so that a signed-in user can only read and change their own company's data. This is enforced in the database itself, not only in the application.
- Do you sell or share customer data?No
- No. We do not sell customer data. Data is shared only with the service providers needed to run Cadence, described in the privacy policy. A list of those providers is available on request.
- How long is data kept, and what happens when we leave?Yes
- Data is kept while the account is active. When an account is deleted, its data is permanently deleted within 30 days, except where we must keep something for legal or regulatory reasons. You can export your data at any time from Settings.
- What are your backup and recovery arrangements?On request
- Available on request. Email hello@cadencefi.co.uk.
Access and accounts
- How do users sign in?Yes
- With an email address and password. Password resets are sent by email. Users join a company only by invitation from an admin.
- Is multi-factor authentication available?No
- Not at present.
- Can we control what each person can do?Yes
- Yes. Each user is either an admin, who can change data and settings, or view-only, who can see everything but change nothing. Admins can remove a user at any time, and a removed user loses access.
- Is there an audit trail?Yes
- Yes. Edits, imports, syncs and settings changes are recorded with who made them and when, and admins can review them.
Connections to other systems
- Does Cadence change data in our accounting software?No
- No. Cadence reads invoices and bills to build the forecast. It does not create, change or delete anything in your accounting software.
- How are connection credentials protected?Yes
- They are stored encrypted, separately from the rest of your data, and are removed when you disconnect or delete your account.
- Can we disconnect an integration?Yes
- Yes, at any time from Settings. An admin can also revoke access from within the connected service.
AI features
- Is our data used to train AI models?No
- No. Our terms state that customer data is not used to train AI models.
- What data do the AI features use?Yes
- Only your own company's data, and only when you use an AI feature or, on Enterprise, when scheduled monitoring runs. The relevant data is sent to an AI provider to produce the answer. AI features are available on the Professional and Enterprise plans, and there is a monthly usage limit on each.
- Can an AI answer contain another customer's data?No
- No. Answers are generated from your company's data only.
Compliance and assurance
- Are you registered with the ICO?On request
- Available on request. Email hello@cadencefi.co.uk.
- Do you hold security certifications?No
- Not at present. We do not currently hold certifications such as ISO 27001 or Cyber Essentials.
- Do you have a data processing agreement?On request
- Available on request. Email hello@cadencefi.co.uk.
- Has the service had an independent penetration test?On request
- Available on request. Email hello@cadencefi.co.uk.
- How would you notify us of a security incident?On request
- Available on request. Email hello@cadencefi.co.uk.
- Where do we report a vulnerability?Yes
- Email hello@cadencefi.co.uk with "Security" in the subject line.
Need something more?
If your organisation has its own supplier questionnaire, send it to hello@cadencefi.co.uk and we will complete it. For how we approach security in general, see Security and your data; for personal data, the privacy policy.
This page is a summary for information and is not a contractual commitment. Contract terms are in our terms of service.