Skip to content
Last updated: Sep 25, 2026

Vendor & Subprocessor Risk Policy ​

Governs how Finaisse assesses and manages the third parties that process its data. Subordinate to the Information Security Policy.

Policy ownerSecurity & Infrastructure Owner (Sekhar Prakash)
Applies toAll third-party services and subprocessors in the data path
Effective2026-08-19 (v0.1 draft)
Review cadenceAnnual + on onboarding a new subprocessor
SOC 2CC9.2

1. Purpose ​

Ensure that third parties processing Finaisse or customer data meet appropriate security and privacy standards, and that customers can be told accurately who processes their data.

2. Subprocessor register ​

The authoritative register of subprocessors — vendor list, data categories, locations, and DPA/assurance status — lives in Data & Privacy → Subprocessors. This policy governs how entries are assessed and onboarded (below); it does not restate the list, so the two never drift.

3. Onboarding assessment ​

Before a new third party processes Finaisse or customer data:

  1. Identify the data classes it will touch (see Data Classification); Restricted data raises the bar.
  2. Review the provider's security assurance (SOC 2 / ISO 27001 report, or a security questionnaire if none).
  3. Ensure an appropriate contract / DPA is in place where personal or customer data is processed.
  4. Record the provider in the subprocessor register.

🎯 Target — formalise this as a checklist gate; today it is applied by the Security & Infrastructure Owner at onboarding.

4. Ongoing management ​

  • The register is reviewed at least annually.
  • 🎯 Target — annual revalidation of each subprocessor's attestation, and reassessment on any material change to what data they process.
  • Removing a subprocessor requires confirming data held by them is returned or destroyed.

5. AI provider specifics ​

LLM providers receive data as part of platform workflows. The commitment that customer data is not used to train third-party models, and the handling controls (redaction, minimisation), are governed under the AI posture (F-14) and must be reflected in the provider DPA. 🎯 Target — finalise before the first production tenant whose data reaches an LLM.

Revision history ​

VersionDateAuthorChange
0.12026-08-19Security & Infrastructure OwnerInitial draft

Finaisse Internal — Confidential. Access-restricted; not for external distribution.