Skip to content
Last updated: Sep 25, 2026

Logging & Monitoring Policy ​

Governs how Finaisse logs security-relevant activity and monitors its systems for threats and availability. Subordinate to the Information Security Policy.

Policy ownerSecurity & Infrastructure Owner (Sekhar)
Applies toAll Finaisse systems and services
Effective2026-08-27 (v0.1 draft)
Review cadenceAnnual + on major architecture change
ClassificationInternal-confidential
ISO / SOC 2A.8.15–8.16 · SOC 2 CC7.2, CC7.3

1. Purpose ​

Ensure security-relevant events are logged, retained, and monitored so incidents can be detected, investigated, and evidenced.

2. Logging ​

  • Security-relevant actions (authentication, authorisation decisions, administrative operations, data-affecting AI decisions) are logged and attributable — the "immutable auditability" principle.
  • No secrets, credentials, or unredacted Restricted data are written to logs. AI-decision reasoning stored in the intelligence log is treated as PII and access-controlled.
  • Application logs carry no full prompt/response content; token-usage and decision metadata are captured (see Observability).

3. Monitoring & detection ​

  • 🎯 Target (AWS) — the Day-1 detection baseline: CloudTrail, GuardDuty, Security Hub, VPC Flow Logs, and WAF logging — a production go-live blocker (F-11).
  • Alerts route to the security owner; suspected incidents follow the Incident Response Policy.

4. Retention & protection ​

  • Logs are retained per the Data Classification & Retention Policy and protected from tampering.
  • 🎯 Target — define per-log-type retention and centralised, access-controlled log storage before production.

5. Review ​

Reviewed annually and on major architecture change.

Revision history ​

VersionDateAuthorChange
0.12026-08-27Security & Infrastructure OwnerInitial draft

Finaisse Internal — Confidential. Access-restricted; not for external distribution.