Trust
What IT will ask
Every question here has come up in a real IT review. The answers describe what the product does today, and where there's no answer yet, we say so.
| Connection | Read-only, one system at a time |
|---|---|
| Credential | Issued by your team, revocable by your team |
| Write access | None. No path, no permission |
| The model | Your key, your provider, your terms |
| Audited by | Big Four ITGC, no major exceptions |
Every one of those, with the mechanism behind it, below.
In short: read-only access through a credential you issue, no write path, your choice of hosting and your choice of AI model. The detail is below.
What you’d be reviewing
| What it is | Sold by | |
|---|---|---|
| FINAHQ | Group statutory reporting: reads every company’s ERP read-only and computes the consolidated statements | One entity in the Ananta Group |
| Munshi | The part of FINAHQ that runs a close step by step and keeps the approval log | The same entity |
| FINK | Management reporting (dimensions, allocations, budget against actual), deployed inside your own infrastructure | The same entity |
This page describes FINAHQ, Munshi and FINK together — all three are offered by the same company.
How FINAHQ connects, per system
Each system connects its own way. OData, for example, is SAP’s standard web interface for reading data.
| System | Versions | How it connects | What it reads | Can it write? |
|---|---|---|---|---|
| Tally | TallyPrime 4.x to 7.x, Tally ERP 9 | Read-only, through Tally's XML interface | Trial balance, Ledgers, AR ageing, AP ageing, Stock reports | No |
| SAP | S/4HANA Cloud and on-premise 2020 to 2024, ECC 6.0 EHP6 and above | Read-only, through OData | Trial balance, Ledgers, AR ageing, AP ageing, Stock reports | No |
| Oracle | Fusion Cloud 23A to 24D, E-Business Suite R12.1 and R12.2 | Read-only, through the GL Balances API | Trial balance, Ledgers, AR ageing, AP ageing, Stock reports | No |
| Oracle NetSuite | All NetSuite accounts | Read-only, through NetSuite's standard interfaces | Trial balance, Ledgers, AR ageing, AP ageing, Stock reports | No |
| Microsoft Dynamics | All versions, including Dynamics 365, NAV and Navision | Scheduled export | Trial balance, Ledgers, AR ageing, AP ageing, Stock reports | No |
| QuickBooks | QuickBooks Online, QuickBooks Online Accountant | Read-only, through OAuth 2.0 | Trial balance, Ledgers, AR ageing, AP ageing, Stock reports | No |
| Zoho Books | All Zoho Books plans | Scheduled export | Trial balance, Ledgers, AR ageing, AP ageing, Stock reports | No |
- You issue the credential. Your team creates it, scopes it and can revoke it without telling us. Acko issued a read-only integration against Oracle Fusion using scoped OAuth (a revocable, limited-permission login), restricted to ledger balances.
- Two rows are exports, not live connections. Dynamics and Zoho Books send a scheduled export, which has a different security profile from a live read.
- Nothing goes back. There is no write path in the product, and no write permission in your credential.
Where it runs
In your infrastructure, on-premise or in your own cloud tenant. The whole stack sits behind your firewall and the ledger data never crosses an external network. TVS Housing runs FINAHQ this way, inside its own Microsoft Azure tenant.
In ours, the standard hosted setup most companies start on. It’s quicker to get going. Data location and deletion on exit are settled in the agreement.
Both are the same product. Swelect Energy Systems runs a group across India, Singapore and the US on SAP. One group not named here onboarded eighteen subsidiaries in four weeks.
Where the AI stops
Code does the arithmetic. The AI handles language. Every figure is worked out by code from your ledgers. The model never computes one, never decides a classification and never reports that a check passed. A check that couldn’t run says NOT VALIDATED. The model reads files, writes the sentences around the figures and asks the questions a ledger can’t answer, so it can’t invent a number it’s never asked to produce.
FINK also deploys inside your infrastructure and makes no third-party AI API calls, so the model provider is your own. More on FINK.
Outside checks and controls
FINAHQ’s applications have been audited by Big Four teams as part of customers’ ITGC audits, with no major exceptions. ITGC means IT general controls: access, change management and operations, examined by the customer’s own statutory auditor.
TVS Housing also took FINAHQ through TVS Group’s internal VAPT (vulnerability assessment and penetration testing) with the group’s Data and AI team. How that deployment works.
| Control | How it works |
|---|---|
| Read-only access to source systems | An account your IT team issues and can revoke, with no write permission and no write path in the product |
| Role-based access | An entity owner sees their entity, a group controller sees the group. In FINK it’s enforced at the query engine |
| Audit trail to the journal entry | Every figure links back to its entry; adjustments are held as approved entries, never overwritten |
| Encryption in transit and at rest | In transit on every connection, at rest in the deployment you choose. Self-hosted, the keys are yours |
| Self-hosting, including on-premise | The whole stack inside your firewall or your own cloud tenant, as at TVS Housing |
| Application-only access | No user has direct database access, and server, network and application accounts carry only the privilege their job needs |
| Account lockout | Accounts lock after repeated failed sign-ins |
On our own cloud deployment — not the self-hosted option above, where your infrastructure sets these — the stack runs on AWS with multi-region replication, continuous backups and a 7-day recovery window.
What we don’t have
- No sub-processors in the ledger path. Where a model runs on our side, it’s a named provider and nothing sits behind it.
Next steps
Procurement can read what it costs and what moves it while you run the security review. And the quickest proof is to have it read your own trial balance, read-only, with your IT team issuing the credentials.
Questions
Commonly asked
Can the product write to our ERP?
No. Every connection is read-only. There is no code path that posts, changes or deletes anything in a source system, and the account your team issues doesn't need write permission. You enforce that control at your end.
Where is our data held?
In the deployment you choose. Self-hosting, fully on-premise or inside your own cloud tenant, is supported, and then the ledger data never leaves your infrastructure. TVS Housing runs it inside its own Microsoft Azure tenant.
Which language model sees our general ledger?
One you choose. Munshi and FINK both support bring-your-own-key, so inference runs on your own account with your own provider, under your contract and retention terms. Where we run a model ourselves, during onboarding for example, it is Anthropic or an equivalent named provider, with no other sub-processors in the path. The model never computes a figure, decides a classification or reports that a check passed. Code does that.
Who inside our organisation can see what?
Access is role-based: an entity owner sees their entity, a group controller sees the group. In FINK that scope is enforced at the query engine, so a plain-English question can't return data outside the asker's scope.
What happens to our data if we stop paying?
Self-hosted, the data stays on your infrastructure and our access ends. If it runs in ours, deletion is a term of the agreement, so ask for it in writing as you would with any vendor.
What can we show an auditor?
Every figure traces to the journal entry it came from, and adjustments are held as approved entries, never overwritten. Munshi, the part of FINAHQ that runs a close step by step, keeps a log of who approved what and when.
FINAHQ and FINK are offered by Ananta Technology Services LLP.