Skip to content
Last updated: Sep 25, 2026

Information Security Policy ​

Master policy of the Finaisse ISMS. All other policies in the policy library derive from and support this one.

Policy ownerSecurity & Infrastructure Owner (Sekhar Prakash)
Approved byCOO (Payeli) — executive sponsor; CEO (Kris) — management commitment
Applies toAll personnel, contractors, systems, and data of Finaisse (Paanini/Finaisse)
Effective2026-08-19 (v0.1 draft)
Review cadenceAnnual, and on major architecture or organisational change
ClassificationInternal-confidential

1. Purpose ​

This policy establishes Finaisse's commitment to protecting the confidentiality, integrity, and availability of the information entrusted to it — in particular the financial data of its multi-tenant customers — and defines the governance framework (the ISMS) under which all other security policies operate.

2. Scope ​

This policy applies to:

  • All Finaisse personnel and contractors.
  • The Finaisse platform: the blitz backend microservices, blitz-ui frontend, and fin-infra infrastructure-as-code.
  • All environments: staging (Railway, live) and production (AWS, in build).
  • All customer data processed by the platform, and all internal data supporting it.
  • All third parties and subprocessors that process Finaisse or customer data (see Vendor & Subprocessor Risk Policy).

3. Policy statements ​

  1. Security is a design requirement, not an add-on. Security requirements are defined alongside functional requirements for every significant capability, with dedicated review for changes touching authentication, tenant boundaries, financial data, or AI. See Secure SDLC Policy.
  2. Information is classified and handled per its sensitivity. Customer financial data is Restricted and receives the strongest controls. See Data Classification & Retention Policy.
  3. Access is least-privilege and accountable. Every access is authenticated, authorised, and auditable. See Access Control Policy.
  4. Changes to production are controlled and traceable. See Change Management Policy.
  5. Incidents are detected, responded to, and learned from. See Incident Response Policy.
  6. The platform is recoverable. See Business Continuity & DR Policy.
  7. Third-party risk is assessed and tracked. See Vendor & Subprocessor Risk Policy.
  8. The posture is measured and driven to closure. Security findings are tracked, severity-ranked, and remediated against defined SLAs. See Findings register and the Secure SDLC Policy.

4. Security principles ​

Finaisse's security is built on six principles (see Security Standards):

  1. Zero Trust by default — no network position, service, or user is inherently trusted.
  2. Defense in depth — independent controls at edge, network, application, and data layers.
  3. Least-privilege access — minimum permission, minimum duration.
  4. Secure by design — controls built into the architecture.
  5. Immutable auditability — security-relevant actions are logged.
  6. Tenant isolation — no customer can access another's data, workload, or identity.

5. Governance & roles ​

RoleResponsibilityCurrent holder
Security & Infrastructure OwnerOwns the ISMS, approves policies, sets risk posture, chairs reviewSekhar Prakash
EngineeringImplements controls, follows SDLC and change policiesAll engineers
All personnelFollow the Acceptable Use Policy; report incidentsEveryone

As the organisation grows, these functional roles will be assigned to additional named individuals; the role definitions remain stable.

6. Risk management ​

Finaisse maintains a security posture across 20 domains mapped to SOC 2, ISO 27001:2022, CIS v8, and OWASP (see Security Domains and Coverage). Risks are:

  • Identified through manual review, ad-hoc scanning (SCA, secret, image, IaC), and — 🎯 Target — CI-gated scanning, SAST/DAST, and an independent penetration test (F-24, F-31).
  • Recorded as severity-ranked findings (P0/P1/P2) in the findings register, each a tracked GitHub issue.
  • Prioritised against the AWS production go-live gate — no item may be 🔴 at go-live.
  • Reviewed at each posture review; open owner-decisions are logged in Standards.

Finaisse targets SOC 2 Type II (Security, Availability, Confidentiality) as its primary attestation, with India DPDP as the near-term privacy baseline and ISO 27001 planned. Applicability of PCI DSS, HIPAA, and GDPR is assessed on a need basis (see Framework & Cert Register).

8. Enforcement ​

Violations of this policy or its subordinate policies may result in revocation of access and, for personnel, disciplinary action. Exceptions must be risk-assessed and approved by the Security & Infrastructure Owner, recorded with an expiry date.

9. Review ​

This policy is reviewed at least annually and upon any major change to the platform architecture, hosting, or organisation. The ISMS owner approves all changes.

Revision history ​

VersionDateAuthorChange
0.12026-08-19Security & Infrastructure OwnerInitial draft

Finaisse Internal — Confidential. Access-restricted; not for external distribution.