Acceptable Use Policy
Governs how Finaisse personnel and contractors use company systems, credentials, and endpoints. Subordinate to the Information Security Policy.
| Policy owner | Security & Infrastructure Owner (Sekhar Prakash) |
| Applies to | All personnel and contractors with access to Finaisse systems |
| Effective | 2026-08-19 (v0.1 draft) |
| Review cadence | Annual + on major change |
| SOC 2 | CC1.4, CC6.7 |
1. Purpose
Set clear expectations for the responsible use of Finaisse systems and data, so that individual behaviour does not undermine the platform's security controls.
2. Acceptable use
- Use Finaisse systems and access only for legitimate work purposes.
- Access customer (Restricted) data only when required for a specific work task, and never copy it outside governed systems.
- Follow all subordinate policies — Access Control, Change Management, Data Classification, Secure SDLC.
3. Credentials & authentication
- Enable and maintain 2FA on GitHub and any service that supports it (2FA is enforced on GitHub).
- Never share credentials, tokens, or API keys. Never commit secrets to source control, paste them into logs/tickets, or send them over insecure channels.
- Report a suspected credential compromise immediately as an incident (see Incident Response).
4. Endpoints
- Keep work devices patched and up to date.
- Use full-disk encryption and screen lock.
- 🎯 Target — a formal endpoint baseline (managed disk encryption, MDM, EDR) as the team grows; developer laptops are currently the perimeter (F-32, Domain 19). Until formalised, the above are individual responsibilities.
5. AI tool use
- When using AI/LLM tools (including in development), do not paste customer Restricted data or secrets into external tools outside governed platform paths.
- The platform's own AI workflows are governed by the AI posture (F-14); this clause covers ad-hoc personal tool use.
6. Prohibited
- Circumventing security controls (e.g. disabling scanning, bypassing review, attaching unauthorised public endpoints to private services).
- Unauthorised access to data or systems beyond one's role.
- Using Finaisse systems for unlawful purposes.
7. Reporting & security awareness
- Report suspected incidents, phishing, or policy violations to the Security & Infrastructure Owner.
- 🎯 Target — annual security-awareness training with completion tracking, and a joiner acknowledgement of this policy (F-33, Domain 20).
8. Enforcement
Violations may result in access revocation and, for personnel, disciplinary action. Exceptions require owner approval with an expiry.
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-19 | Security & Infrastructure Owner | Initial draft |