Skip to content
Last updated: Sep 25, 2026

Subprocessors ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal0.12026-08-272026-11-27Draft

Purpose. The authoritative internal record of third parties that process customer data on Finaisse's behalf. It supports subprocessor and data-processing-agreement requests and vendor onboarding review. A sanitised public version is maintained in the external Trust Centre.

How to read ​

Each entry records purpose, data category, location, and data-processing-agreement status. Any newly added vendor that processes customer data must appear here. Governed by the Vendor & Subprocessor Risk policy.

Register ​

The parties in the data path. This is the authoritative register; the Vendor & Subprocessor Risk policy governs how entries are assessed and onboarded. Verify this register before any external (customer) use; the sanitised public version lives in the external Trust Centre.

SubprocessorPurpose / roleData categoryLocationAssurance / DPAAdded
RailwayStaging hosting, compute, managed PostgresStaging data (no production tenants yet)— (staging)Provider security posture — 🎯 assess/record—
AWSProduction hosting (in build)Production customer data (future) — all classesap-south-1 (Mumbai)SOC 2 / ISO (AWS-provided)—
CloudflareEdge — DDoS, CDN, TLS, AccessTraffic in transit; no data at restGlobal edgeSOC 2 / ISO (provider)—
GitHub (GHCR)Source control + container registrySource + images (no customer data)—SOC 2 (provider)—
ZohoIdentity / emailOperator identity + email—Provider posture — 🎯 record—
GoogleAPI services (per feature)As configured per feature—Provider posture — 🎯 record—
TemporalWorkflow orchestrationWorkflow payloads (carry tenant financial data)⚠️ self-hosted on Railway today vs Temporal Cloud — confirmInherits host (Railway) today — 🎯 record—
Object storage (RustFS / S3)Tenant file & object storageRestricted data at rest (files, uploads)Self-hosted on Railway today; AWS S3 at prodInherits host today; AWS SSE/KMS at prod (F-18)—
ValkeyCacheTenant data cached in memory/transitSelf-hosted on Railway todayInherits host (Railway) today—
Google (Gemini)LLM inference — Finni default (live)Data sent to model — tokenised financial / PIIRegion-pinned (target)⚠️ currently a free AI-Studio key whose terms permit training — must move to a no-train enterprise endpoint + DPA (F-14)—
OpenAILLM inference — wired (OPENAI_API_KEY)Data sent to model (when selected)—🎯 confirm whether live; DPA if used—
Cloudflare PagesInternal docs hosting (this site)No customer data (internal docs only)Global edgeSOC 2 / ISO (provider)—

🎯 Target — complete the "Assurance / DPA" and "Added" columns with each provider's current attestation (SOC 2 / ISO report or equivalent) and DPA where customer data is involved. Any newly added vendor that processes customer data must be added here.

⚠️ Verify before external/audit use. Rows marked ⚠️ were inferred from code/IaC, not confirmed operationally: whether Temporal is self-hosted vs Temporal Cloud, and whether OpenAI is live or only wired. The Temporal/RustFS/Valkey entries are self-hosted on Railway today, so they are arguably Railway infrastructure rather than distinct subprocessors — but they become separate at AWS, and object storage holds Restricted data, so they are named explicitly here.

Customer-configured integrations (connectors) — not Finaisse subprocessors ​

Distinct category. These external systems are connected by a customer using their own credentials (stored per-tenant, encrypted — connectorcredential / credentialcrypto). Finaisse is a conduit that moves data to/from them at the tenant's direction; the customer owns the credential and the DPA relationship with that vendor. They are not Finaisse subprocessors, but they are data ingress/egress points and are listed for completeness.

ConnectorDirectionDataCredential owner
SAPin/outERP / financial master + transactionsTenant
Xeroin/outAccounting dataTenant
Zoho Booksin/outAccounting dataTenant
SharePointin/outDocumentsTenant
Salesforcein/outCRM / customer dataTenant
NetSuitein/outERP dataTenant
QuickBooksin/outAccounting dataTenant

These are per-tenant and enabled selectively — a given tenant may use none, one, or several. See Data Flows → Ingress for how connector data enters the platform.

Revision history ​

VersionDateAuthorChange
0.12026-08-27Sekhar PrakashInitial structure.
0.22026-08-28Sekhar PrakashPopulated the register with the 7 current subprocessors (moved from the Vendor & Subprocessor Risk policy, which now links here as the authoritative source).
0.32026-08-28Sekhar PrakashCompleteness review vs code/IaC: added Temporal, object storage (RustFS/S3), Valkey, docs host; named live LLM providers (Gemini default, OpenAI wired); added a separate "customer-configured integrations (connectors)" section (SAP/Xero/Zoho Books/SharePoint/Salesforce/NetSuite/QuickBooks). ⚠️ inferred rows flagged for operational confirmation.
0.42026-08-28Sekhar PrakashConfirmed docs host = Cloudflare Pages (not Vercel — nothing on Vercel); resolved that ⚠️ row.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.