Skip to content
Last updated: Sep 25, 2026

Finaisse Policy Library (ISMS) ​

The Finaisse Information Security Management System (ISMS) policy set. These are the governing documents behind the security posture and the system description — the "documented process" half of SOC 2 that technical controls alone do not satisfy.

Status: initial draft — target-state with dated controls

Finaisse is pre-production. These policies are written as the intended steady state, and controls not yet fully operating are marked 🎯 Target with an owner and expected date. That is deliberate and audit-honest: a SOC 2 Type II examination tests whether controls operated over a window, so a policy that claims a control already runs when it does not is worse than one that states the target and date. As each control lands, remove its 🎯 marker and record the change in the document's revision history.

ISMS ownerSekhar Prakash — Security & Infrastructure
Applies toAll Finaisse personnel, contractors, systems, and the Finaisse platform
Review cadenceAnnual, and on major architecture or organisational change
Current stagePre-production; staging on Railway, AWS production being built

Policies ​

#PolicyCoversSOC 2 (TSC)
1Information Security PolicyMaster policy — ISMS scope, governance, principlesCC1, CC2, CC3, CC5
2Access Control PolicyIdentity, authentication, authorisation, reviewsCC6.1–6.3
3Change Management PolicyCode/infra change, review, deployment, releaseCC8.1
4Incident Response PolicyDetection, response, escalation, notificationCC7.3–7.5
5Business Continuity & Disaster Recovery PolicyBackups, RTO/RPO, recovery, resilienceA1.2, A1.3
6Vendor & Subprocessor Risk PolicyThird-party assessment, subprocessor registerCC9.2
7Secure Development Lifecycle PolicySecure design, testing, vulnerability managementCC7.1, CC8.1
8Data Classification & Retention PolicyClassification, handling, retention, deletionC1, CC6.5, P
9Acceptable Use PolicyPersonnel use of systems, endpoints, credentialsCC1.4, CC6.7
10Risk Management PolicyRisk identification, assessment, treatment, acceptanceCC3.1–3.4
11Cryptography & Key Management PolicyEncryption in transit/at rest, key & secret lifecycleCC6.1, CC6.7
12Human Resources Security & Awareness PolicyPersonnel lifecycle, security awareness trainingCC1.4, CC2.2
13Privacy & Data Protection PolicyLawful processing, data-subject rights, breachP, C1
14Asset Management PolicyAsset inventory, ownership, disposalCC6.1
15Logging & Monitoring PolicySecurity logging, monitoring, retentionCC7.2, CC7.3
16Physical & Environmental Security PolicyHosting (cloud-inherited), endpointsA.7
17Code of Conduct & EthicsProfessional & ethical standardsCC1.1
18Mobile Device & Remote Working PolicyEndpoint & remote-access securityA.6.7

Ownership ​

Each policy is owned by the accountable function, and the ISMS is approved at senior-management level (demonstrating SOC 2 CC1 / ISO clause 5 commitment):

  • Security & Infrastructure Owner (Sekhar) — technical security policies (1–4, 7, 10, 11, 14, 15, 18).
  • COO (Payeli) — people, privacy, and operational policies (5, 9, 12, 13, 16, 17).
  • Approver — COO (Payeli) as executive sponsor; CEO (Kris) for management commitment on the master policy.

The governance map is the ISMS Scope & Framework.

ISO 27001 mandatory ISMS documents (distinct from policies; required only for ISO certification, not SOC 2): ISMS scope statement, security objectives, risk assessment methodology (covered by the Risk Management Policy), Statement of Applicability ✅, internal audit programme, management review records. These sit under the ISMS governance layer — see the ISMS Scope & Framework and System Description — and are placeholders until ISO is pursued.

How these relate to the rest of the docs ​

  • Security domains and coverage describe what we protect and how well; these policies state the rules and responsibilities that govern it.
  • Platform Operations holds the operational procedures a policy points to (e.g. the Incident Response Policy sets the rules; Run & Operate is the step-by-step).
  • Findings register tracks the engineering work to close gaps these policies mark as 🎯 Target.

Conventions ​

  • 🎯 Target — a control this policy commits to that is not yet fully operating; carries an owner + expected date.
  • Owner / Approver — functional roles; where a named person is required today, that is the ISMS owner (Sekhar Prakash) until the team grows.
  • Each policy carries a revision history; material changes require ISMS-owner approval.

Access & handling

Internal-confidential. Restricted to members of the finaisse-org GitHub organization. These are governing documents, not customer-shareable marketing — a customer trust summary is derived separately.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.