Physical & Environmental Security Policy
Governs physical and environmental protection of the systems that process Finaisse data. Subordinate to the Information Security Policy.
| Policy owner | COO (Payeli) |
| Applies to | Hosting environments and personnel endpoints |
| Effective | 2026-08-27 (v0.1 draft) |
| Review cadence | Annual |
| Classification | Internal-confidential |
| ISO | A.7 |
1. Purpose
Define how physical and environmental risks to Finaisse data are managed. Finaisse operates no owned data centres; production and staging run on cloud providers.
2. Cloud hosting (inherited controls)
Physical and environmental security of the underlying infrastructure — facility access, power, cooling, fire suppression, hardware disposal — is the responsibility of the cloud providers (AWS, Railway) and is relied upon under their SOC 2 / ISO 27001 attestations. These attestations are recorded in the Subprocessors register.
3. Endpoints
- Personnel access company systems from endpoints governed by the Acceptable Use and Mobile Device & Remote Working policies.
- 🎯 Target — baseline endpoint controls (disk encryption, screen lock, current OS/patches) as the team grows.
4. Review
Reviewed annually.
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | COO | Initial draft |