Information Security Policy
Master policy of the Finaisse ISMS. All other policies in the policy library derive from and support this one.
| Policy owner | Security & Infrastructure Owner (Sekhar Prakash) |
| Approved by | COO (Payeli) — executive sponsor; CEO (Kris) — management commitment |
| Applies to | All personnel, contractors, systems, and data of Finaisse (Paanini/Finaisse) |
| Effective | 2026-08-19 (v0.1 draft) |
| Review cadence | Annual, and on major architecture or organisational change |
| Classification | Internal-confidential |
1. Purpose
This policy establishes Finaisse's commitment to protecting the confidentiality, integrity, and availability of the information entrusted to it — in particular the financial data of its multi-tenant customers — and defines the governance framework (the ISMS) under which all other security policies operate.
2. Scope
This policy applies to:
- All Finaisse personnel and contractors.
- The Finaisse platform: the
blitzbackend microservices,blitz-uifrontend, andfin-infrainfrastructure-as-code. - All environments: staging (Railway, live) and production (AWS, in build).
- All customer data processed by the platform, and all internal data supporting it.
- All third parties and subprocessors that process Finaisse or customer data (see Vendor & Subprocessor Risk Policy).
3. Policy statements
- Security is a design requirement, not an add-on. Security requirements are defined alongside functional requirements for every significant capability, with dedicated review for changes touching authentication, tenant boundaries, financial data, or AI. See Secure SDLC Policy.
- Information is classified and handled per its sensitivity. Customer financial data is Restricted and receives the strongest controls. See Data Classification & Retention Policy.
- Access is least-privilege and accountable. Every access is authenticated, authorised, and auditable. See Access Control Policy.
- Changes to production are controlled and traceable. See Change Management Policy.
- Incidents are detected, responded to, and learned from. See Incident Response Policy.
- The platform is recoverable. See Business Continuity & DR Policy.
- Third-party risk is assessed and tracked. See Vendor & Subprocessor Risk Policy.
- The posture is measured and driven to closure. Security findings are tracked, severity-ranked, and remediated against defined SLAs. See Findings register and the Secure SDLC Policy.
4. Security principles
Finaisse's security is built on six principles (see Security Standards):
- Zero Trust by default — no network position, service, or user is inherently trusted.
- Defense in depth — independent controls at edge, network, application, and data layers.
- Least-privilege access — minimum permission, minimum duration.
- Secure by design — controls built into the architecture.
- Immutable auditability — security-relevant actions are logged.
- Tenant isolation — no customer can access another's data, workload, or identity.
5. Governance & roles
| Role | Responsibility | Current holder |
|---|---|---|
| Security & Infrastructure Owner | Owns the ISMS, approves policies, sets risk posture, chairs review | Sekhar Prakash |
| Engineering | Implements controls, follows SDLC and change policies | All engineers |
| All personnel | Follow the Acceptable Use Policy; report incidents | Everyone |
As the organisation grows, these functional roles will be assigned to additional named individuals; the role definitions remain stable.
6. Risk management
Finaisse maintains a security posture across 20 domains mapped to SOC 2, ISO 27001:2022, CIS v8, and OWASP (see Security Domains and Coverage). Risks are:
- Identified through manual review, ad-hoc scanning (SCA, secret, image, IaC), and — 🎯 Target — CI-gated scanning, SAST/DAST, and an independent penetration test (F-24, F-31).
- Recorded as severity-ranked findings (P0/P1/P2) in the findings register, each a tracked GitHub issue.
- Prioritised against the AWS production go-live gate — no item may be 🔴 at go-live.
- Reviewed at each posture review; open owner-decisions are logged in Standards.
7. Compliance & legal
Finaisse targets SOC 2 Type II (Security, Availability, Confidentiality) as its primary attestation, with India DPDP as the near-term privacy baseline and ISO 27001 planned. Applicability of PCI DSS, HIPAA, and GDPR is assessed on a need basis (see Framework & Cert Register).
8. Enforcement
Violations of this policy or its subordinate policies may result in revocation of access and, for personnel, disciplinary action. Exceptions must be risk-assessed and approved by the Security & Infrastructure Owner, recorded with an expiry date.
9. Review
This policy is reviewed at least annually and upon any major change to the platform architecture, hosting, or organisation. The ISMS owner approves all changes.
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-19 | Security & Infrastructure Owner | Initial draft |