Governance, Security and Compliance (GRC)
The security and compliance area for the Finaisse platform (multi-tenant financial SaaS). Choose an area below.
Explore this area
Security Posture
Maturity, P0 blockers, findings, go-live gate
System DescriptionThe system for audit — components, boundaries, subprocessors (SOC 2 §III)
ISMS Scope & FrameworkScope, objectives, governance map
Controls & ComplianceControl register, crosswalk, evidence, SoA
Frameworks & CertificationsSOC 2, SOC 1, ISO 27001 / 42001 strategy
Assessment & Evidence CadenceWhat runs when, who owns it, where evidence lands
Data & PrivacyRoPA, data flows, subprocessors
AI GovernanceLLM tokenization, DPIA, compliance
Policy Library (ISMS)18 information-security policies
Programme HistoryTimeline of the security programme
At a glance: 4 P0 findings open (down from 8) · SOC 2 Type II target · India DPDP baseline · last reconciled 2026-09-10. Full state in Security Posture.
Related
Engineering docs: Platform Operations · Architecture
Access & handling
Restricted to members of the finaisse-org GitHub organization (Cloudflare Access, GitHub org-membership policy). Internal-confidential — do not share findings, issue links, or screenshots outside Finaisse.