Skip to content
Last updated: Sep 25, 2026

Data Flows ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal0.12026-08-272026-11-27Draft

Purpose. Documents how customer and personal data moves through the platform across four stages — ingress, inter-service transfer, the model boundary, and egress. Supports data-protection impact assessments and verifies that each flow crossing the trust boundary is controlled and logged.

Scope and method ​

Four egress points carry sensitive data (per the tokenization design):

  • The model prompt.
  • The intelligence-log reasoning field.
  • Application logs.
  • Conversation-checkpoint state.

Each flow in the table below is described by four fields: source, transform (tokenise or encrypt), destination, and retention.

Flows ​

FlowSourceTransformDestinationState
IngressUploads, email, connectors (SAP, Xero, Zoho Books, SharePoint, Salesforce, NetSuite, QuickBooks — tenant-credentialed)Classification at boundaryData storesTo be defined
Inter-serviceService to serviceTenant scoping, TLSData storesTo be defined
Model boundaryTool output / promptTokenise, then de-tokenise on returnExternal LLMTo be defined
EgressLogs, tracing, exportsRedactionExternal systemsTo be defined

Flow diagrams to be embedded during completion.

Actions and owners ​

To be derived from the tokenization and compliance-readiness findings.

Revision history ​

VersionDateAuthorChange
0.12026-08-27Sekhar PrakashInitial structure.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.