Integrations

One card per source category, data flows in from anywhere.

View all integrations →

The Agentic Layer

The governed foundation — platform capabilities.

Reporting & Analysis

Business performance tracking, variance, and analytical insight.

See all →

Planning & Modeling

A comprehensive look at forward-looking corporate financial strategy.

See all →

Consolidation & Close

The entire financial close and data management cycle, at a high level.

See all →
Cube Security: AI You Can Audit | Cube
Security at Cube · SOC 2 Type II · HIPAA

AI you can audit.

Cube is SOC 2 Type II certified FP&A software where every AI answer is permission-checked, logged, and traceable to the source transaction.

Scroll
The stance

With AI in finance, trust is a mandate. Cube builds compliance, permissions, and traceability into every layer.

From the login to the AI answer, nothing moves through Cube without a rule applied and a record kept.

Vendor review

Everything IT needs, ready before they ask.

Transparency is the default: the documents live in the open, and the team behind them picks up when you call.

/01
Is it audited?

Certified

SOC 2 Type II, examined by Dansa D'Arata Soucia. HIPAA compliant, on AWS infrastructure. Reports available on request.

/02
Who sees what?

Controlled

Role-based access on every surface: the Cube app, connected spreadsheets, and reports. The same rules are enforced for the AI.

/03
Can we verify it?

Traceable

Every figure and every AI answer drills to the source transactions behind it. Audit questions become clicks.

Your most sensitive data, held to the highest standard.

100%
encrypted in transit and at rest
SOC 2
Type II, examined annually
HIPAA
compliant data handling
FP&Agents, on the record

Every AI action, logged.

Cube's FP&Agents run on your governed model. Queries, answers, and publishes are recorded with the user, the permission scope applied, and the sources used. Denied actions are logged too. More at AI at Cube.

every query · every answer · every publish · every denial

In the product

The checklist, answered before you send it.

The same permissions govern the Cube app, connected spreadsheets, reports, and FP&Agents. See access control in Cube for the full model.

Book a demo
/01

Role-based access

Permissions set once follow the user into the app, spreadsheets, and reports.

/02

AI under the same rules

FP&Agents inherit the permissions of the person asking. Denied means denied.

/03

SAML single sign-on

Your identity provider controls every login to Cube.

/04

Multi-factor authentication

App-based or text-based MFA on every account.

/05

Full audit logs

Every fetch, publish, and permission change is logged and reviewable.

/06

Encryption everywhere

TLS in transit and encryption at rest, on secure AWS infrastructure.

Under the hood

Compliance you can check, on infrastructure you already trust.

SOC 2

Type II certified

Examined by Dansa D'Arata Soucia. Reports available on request.

HIPAA

Compliant

Safeguards built for handling sensitive and regulated data.

100%

Encrypted

TLS in transit and encryption at rest, always on.

AWS

Cloud infrastructure

Internal systems stay off the public internet, behind separate access controls.

Bring the security questionnaire.

See Cube with your IT checklist in hand. We answer the controls questions live, with the AI audit log open.

Book a demo

Prefer to start with documents? Visit the Trust Center

FAQ

Questions security teams ask.

Yes. Cube has completed a SOC 2 Type II examination conducted by Dansa D'Arata Soucia, and certifications are kept current in the Cube Trust Center. The full report is available on request.
Yes. FP&Agent activity is logged with the user, the permission scope applied, and the sources used, and every AI-assisted figure traces to the accounts and transactions behind it. Reviewing the AI means reading the log, then clicking through to source.
FP&Agents work inside your governed Cube model and inherit each user's permissions, so an agent only uses data the person asking is allowed to see. Every AI-assisted figure traces back to the accounts and transactions behind it.
Access in Cube is role-based. Admins set permissions once and they follow each user across every surface, including the Cube app, connected spreadsheets, and reports. The same rules are enforced for FP&Agents.
Cube runs on Amazon Web Services infrastructure. Data is encrypted over TLS in transit and encrypted at rest, and internal systems sit behind separate access controls that are never exposed to the public internet.
Yes. Cube supports SAML single sign-on so your identity provider controls every login, plus multi-factor authentication through an authenticator app or text message.
Start at the Cube Trust Center for current certifications and controls. Security reports are available on request, our team supports your questionnaire, and we join vendor review calls when your IT team wants a live walkthrough.