Skip to content
Last updated: Sep 25, 2026

Acceptable Use Policy ​

Governs how Finaisse personnel and contractors use company systems, credentials, and endpoints. Subordinate to the Information Security Policy.

Policy ownerSecurity & Infrastructure Owner (Sekhar Prakash)
Applies toAll personnel and contractors with access to Finaisse systems
Effective2026-08-19 (v0.1 draft)
Review cadenceAnnual + on major change
SOC 2CC1.4, CC6.7

1. Purpose ​

Set clear expectations for the responsible use of Finaisse systems and data, so that individual behaviour does not undermine the platform's security controls.

2. Acceptable use ​

3. Credentials & authentication ​

  • Enable and maintain 2FA on GitHub and any service that supports it (2FA is enforced on GitHub).
  • Never share credentials, tokens, or API keys. Never commit secrets to source control, paste them into logs/tickets, or send them over insecure channels.
  • Report a suspected credential compromise immediately as an incident (see Incident Response).

4. Endpoints ​

  • Keep work devices patched and up to date.
  • Use full-disk encryption and screen lock.
  • 🎯 Target — a formal endpoint baseline (managed disk encryption, MDM, EDR) as the team grows; developer laptops are currently the perimeter (F-32, Domain 19). Until formalised, the above are individual responsibilities.

5. AI tool use ​

  • When using AI/LLM tools (including in development), do not paste customer Restricted data or secrets into external tools outside governed platform paths.
  • The platform's own AI workflows are governed by the AI posture (F-14); this clause covers ad-hoc personal tool use.

6. Prohibited ​

  • Circumventing security controls (e.g. disabling scanning, bypassing review, attaching unauthorised public endpoints to private services).
  • Unauthorised access to data or systems beyond one's role.
  • Using Finaisse systems for unlawful purposes.

7. Reporting & security awareness ​

  • Report suspected incidents, phishing, or policy violations to the Security & Infrastructure Owner.
  • 🎯 Target — annual security-awareness training with completion tracking, and a joiner acknowledgement of this policy (F-33, Domain 20).

8. Enforcement ​

Violations may result in access revocation and, for personnel, disciplinary action. Exceptions require owner approval with an expiry.

Revision history ​

VersionDateAuthorChange
0.12026-08-19Security & Infrastructure OwnerInitial draft

Finaisse Internal — Confidential. Access-restricted; not for external distribution.