Skip to content
Finanly

The platform

This is the product. Not a mockup.

Every screen below is a capture of the Finanly web app as it ships — light and dark, desktop and phone — and every diagram is the architecture that actually runs it.

Finanly transactions workspace with bank cards and the review queue, light theme
Finanly Ask Your Books on a phone, dark theme
Finanly transactions on a phone, light theme

Actual captures of the Finanly web app on a demo company — desktop and phone. Nothing is mocked or generated.

Inside the app

Seven areas, as they really look.

Pick an area, or let it play. Every frame is a capture of the app on a demo company.

Capture: Finanly transactions workspace with a categorization panel open under a bank transaction row.

One row, one decision, one click.

Bank feeds land here already sorted. Each row carries vendor, GL account, cost center and subscription controls inline; open a row to categorize, match, split, exclude or record a transfer.

How the close works

Architecture

One enforcement point. Everything else is internal.

The browser only ever talks to core-api. Connectors, the AI gateway, workers and the compliance engine live on a private network and are called with short-lived service tokens.

Browserfinanly.ai · app.finanly.ai
edgeTLS · routing · rate limits
core-apithe single enforcement point
private network · internal JWT · no host ports
ai-gatewayFinanly 8B finance model
jobs · beatCelery workers + schedule
compliancemass balance · trace-back
connector-*mercury · plaid · shopify · flexport · paypal · wise · ga4 · erpnext
Postgrescanonical store · RLS per tenant
Cubesemantic layer · 18 cubes
audit_eventsappend-only (DB trigger)
Redisqueues · idempotency locks

core-api

FastAPI. Auth, tenant context, plan gating, workflows, canonical store, audit events. The only public API.

ai-gateway

Internal-only. Serves Finanly's own 8B finance model on your hardware; strict schemas; no irreversible actions.

connectors

One stateless service per integration — Mercury, Plaid, Shopify, Flexport, PayPal, Wise, GA4, ERPNext — each holding only its own credentials.

jobs + beat

Celery workers and scheduler: nightly sync-all, webhooks, backfills, exports, report runs, statement parity.

canonical store

Postgres with row-level security on every tenant table; Cube semantic layer on top for BI.

audit store

audit_events is append-only at the database level: a trigger rejects updates and deletes.

A platform you can acquire is one where the boundaries are real: one public door, private everything else, and a log that cannot be edited.

Multi-company

Four companies, one login, zero leakage.

Each company is a tenant. Switching sets the tenant context for every query; Postgres row-level security enforces it underneath the application, not just in it.

BusinessNourishing Inc
  • Mercury · Plaid
  • ERPNext ledger
  • Cost centers
WHERE tenant_id = current_setting('app.tenant_id')
BusinessPascucci USA
  • Shopify · Flexport
  • Landed cost
  • COGS sync
WHERE tenant_id = current_setting('app.tenant_id')
BusinessFine Line LLC
  • Plaid · EUR accounts
  • FX revaluation
  • Simple books
WHERE tenant_id = current_setting('app.tenant_id')
PersonalLuca Personal
  • Safe-to-spend
  • Baskets
  • Subscriptions
WHERE tenant_id = current_setting('app.tenant_id')

Business & Personal modes

A tenant is either a company with cost centers and a ledger, or a personal space with baskets and a planner. Same login, different sidebar.

Plans gate features

Every capability is a registered feature key checked at the endpoint and in the UI; plans assign them. Stripe subscriptions drive the entitlement.

Roles inside a tenant

Owner, admin, member. Admin-only endpoints (sync controls, ledger sync, pricing) sit behind an extra IP allowlist at the edge.

Audit trail

Every action is on the record.

Every irreversible action writes an audit event that cannot be updated or deleted. Side-effect endpoints also take an Idempotency-Key: a replay returns the original response, a changed payload returns 409.

audit_events · append-only · tenant 9f26…0021
timeactoreventreference
09:41:03luca@…txn.categorizeIdempotency-Key 7f3a…c1
09:41:03core-apiexport_batch.item_createderpnext JE-2026-00412
09:41:09luca@…txn.categorize (replay)same key → stored 200
09:42:17luca@…txn.categorize (changed payload)same key → 409 idempotency_conflict
09:44:52luca@…txn.undo_categorizationreversal JE-2026-00413
09:45:00jobs-beatfinancial_statements.parity_checkBS / P&L / TB · pass

Illustrative rows — the shapes are real event names from core-api; the values are sample data.

100%of side-effect endpoints require Idempotency-Key
409returned when a key is replayed with a different payload
0UPDATE or DELETE allowed on audit_events
1public API — everything else is internal

Light & dark

Two themes. Same numbers.

Light by default for dense tables; dark when you want it. The dark cockpit sidebar is the one constant — it's how you know you're in Finanly.

Finanly with the sidebar collapsed to an icon rail
Collapse the rail when the table needs the room
Finanly command palette open over the transactions page in dark theme
⌘K goes anywhere

On your phone

The same app, in your pocket.

Responsive, not a separate product: the drawer, the tables and the ask box all work at 390 pixels.

Finanly transactions on a phone
Finanly navigation drawer on a phone
Finanly Ask Your Books on a phone

FAQ

Straight answers

Is this a rebrand of an accounting package?

No. Finanly is a standalone codebase and container stack: Next.js UI, FastAPI core-api, Celery jobs, one FastAPI service per connector, an internal AI gateway and Postgres. ERPNext is today's ledger of record behind a connector; it is not the product.

Where does it run?

On your own hardware or VPS, as a Docker Compose stack. Only the UI, core-api and the read-only status page are exposed behind the edge; every other service is on a private network with no host ports.

How is one company kept away from another?

Each request carries a tenant context; Postgres row-level security policies on every tenant table filter rows by that context. The application also filters by tenant_id explicitly — two layers, not one.

What if the same export is sent twice?

Side-effect endpoints require an Idempotency-Key. A replay returns the stored response; the ledger connector uses the same key so the posting is created once. A different payload under the same key is rejected with 409.

Can I switch the ledger later?

That is the design: ledger connectors implement a capability matrix (accounts, dimensions, counterparties, postings, reports). ERPNext is the full reference implementation; QuickBooks Online and Xero are planned with an MVP subset first.

Is the AI part optional?

Yes. Categorization falls back to exact and similarity matching from your own history; BI still runs governed fallbacks for cash, AR, AP, balance sheet and P&L. The private model adds disambiguation and free-form questions.

Are the screenshots real?

They are captures of the running app on a demo company, taken by a script against the same build that serves finanly.ai. Nothing is generated or mocked.

See it on your own ledger.

Private beta. Tell us where to send your access, and which company you close first.