Vendor & Subprocessor Risk Policy
Governs how Finaisse assesses and manages the third parties that process its data. Subordinate to the Information Security Policy.
| Policy owner | Security & Infrastructure Owner (Sekhar Prakash) |
| Applies to | All third-party services and subprocessors in the data path |
| Effective | 2026-08-19 (v0.1 draft) |
| Review cadence | Annual + on onboarding a new subprocessor |
| SOC 2 | CC9.2 |
1. Purpose
Ensure that third parties processing Finaisse or customer data meet appropriate security and privacy standards, and that customers can be told accurately who processes their data.
2. Subprocessor register
The authoritative register of subprocessors — vendor list, data categories, locations, and DPA/assurance status — lives in Data & Privacy → Subprocessors. This policy governs how entries are assessed and onboarded (below); it does not restate the list, so the two never drift.
3. Onboarding assessment
Before a new third party processes Finaisse or customer data:
- Identify the data classes it will touch (see Data Classification); Restricted data raises the bar.
- Review the provider's security assurance (SOC 2 / ISO 27001 report, or a security questionnaire if none).
- Ensure an appropriate contract / DPA is in place where personal or customer data is processed.
- Record the provider in the subprocessor register.
🎯 Target — formalise this as a checklist gate; today it is applied by the Security & Infrastructure Owner at onboarding.
4. Ongoing management
- The register is reviewed at least annually.
- 🎯 Target — annual revalidation of each subprocessor's attestation, and reassessment on any material change to what data they process.
- Removing a subprocessor requires confirming data held by them is returned or destroyed.
5. AI provider specifics
LLM providers receive data as part of platform workflows. The commitment that customer data is not used to train third-party models, and the handling controls (redaction, minimisation), are governed under the AI posture (F-14) and must be reflected in the provider DPA. 🎯 Target — finalise before the first production tenant whose data reaches an LLM.
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-19 | Security & Infrastructure Owner | Initial draft |