Subprocessors
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Sekhar Prakash | Internal | 0.1 | 2026-08-27 | 2026-11-27 | Draft |
Purpose. The authoritative internal record of third parties that process customer data on Finaisse's behalf. It supports subprocessor and data-processing-agreement requests and vendor onboarding review. A sanitised public version is maintained in the external Trust Centre.
How to read
Each entry records purpose, data category, location, and data-processing-agreement status. Any newly added vendor that processes customer data must appear here. Governed by the Vendor & Subprocessor Risk policy.
Register
The parties in the data path. This is the authoritative register; the Vendor & Subprocessor Risk policy governs how entries are assessed and onboarded. Verify this register before any external (customer) use; the sanitised public version lives in the external Trust Centre.
| Subprocessor | Purpose / role | Data category | Location | Assurance / DPA | Added |
|---|---|---|---|---|---|
| Railway | Staging hosting, compute, managed Postgres | Staging data (no production tenants yet) | — (staging) | Provider security posture — 🎯 assess/record | — |
| AWS | Production hosting (in build) | Production customer data (future) — all classes | ap-south-1 (Mumbai) | SOC 2 / ISO (AWS-provided) | — |
| Cloudflare | Edge — DDoS, CDN, TLS, Access | Traffic in transit; no data at rest | Global edge | SOC 2 / ISO (provider) | — |
| GitHub (GHCR) | Source control + container registry | Source + images (no customer data) | — | SOC 2 (provider) | — |
| Zoho | Identity / email | Operator identity + email | — | Provider posture — 🎯 record | — |
| API services (per feature) | As configured per feature | — | Provider posture — 🎯 record | — | |
| Temporal | Workflow orchestration | Workflow payloads (carry tenant financial data) | ⚠️ self-hosted on Railway today vs Temporal Cloud — confirm | Inherits host (Railway) today — 🎯 record | — |
| Object storage (RustFS / S3) | Tenant file & object storage | Restricted data at rest (files, uploads) | Self-hosted on Railway today; AWS S3 at prod | Inherits host today; AWS SSE/KMS at prod (F-18) | — |
| Valkey | Cache | Tenant data cached in memory/transit | Self-hosted on Railway today | Inherits host (Railway) today | — |
| Google (Gemini) | LLM inference — Finni default (live) | Data sent to model — tokenised financial / PII | Region-pinned (target) | ⚠️ currently a free AI-Studio key whose terms permit training — must move to a no-train enterprise endpoint + DPA (F-14) | — |
| OpenAI | LLM inference — wired (OPENAI_API_KEY) | Data sent to model (when selected) | — | 🎯 confirm whether live; DPA if used | — |
| Cloudflare Pages | Internal docs hosting (this site) | No customer data (internal docs only) | Global edge | SOC 2 / ISO (provider) | — |
🎯 Target — complete the "Assurance / DPA" and "Added" columns with each provider's current attestation (SOC 2 / ISO report or equivalent) and DPA where customer data is involved. Any newly added vendor that processes customer data must be added here.
⚠️ Verify before external/audit use. Rows marked ⚠️ were inferred from code/IaC, not confirmed operationally: whether Temporal is self-hosted vs Temporal Cloud, and whether OpenAI is live or only wired. The Temporal/RustFS/Valkey entries are self-hosted on Railway today, so they are arguably Railway infrastructure rather than distinct subprocessors — but they become separate at AWS, and object storage holds Restricted data, so they are named explicitly here.
Customer-configured integrations (connectors) — not Finaisse subprocessors
Distinct category. These external systems are connected by a customer using their own credentials (stored per-tenant, encrypted — connectorcredential / credentialcrypto). Finaisse is a conduit that moves data to/from them at the tenant's direction; the customer owns the credential and the DPA relationship with that vendor. They are not Finaisse subprocessors, but they are data ingress/egress points and are listed for completeness.
| Connector | Direction | Data | Credential owner |
|---|---|---|---|
| SAP | in/out | ERP / financial master + transactions | Tenant |
| Xero | in/out | Accounting data | Tenant |
| Zoho Books | in/out | Accounting data | Tenant |
| SharePoint | in/out | Documents | Tenant |
| Salesforce | in/out | CRM / customer data | Tenant |
| NetSuite | in/out | ERP data | Tenant |
| QuickBooks | in/out | Accounting data | Tenant |
These are per-tenant and enabled selectively — a given tenant may use none, one, or several. See Data Flows → Ingress for how connector data enters the platform.
Related
- → Vendor & Subprocessor Risk policy
- → Records of Processing — the processing these vendors support
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Sekhar Prakash | Initial structure. |
| 0.2 | 2026-08-28 | Sekhar Prakash | Populated the register with the 7 current subprocessors (moved from the Vendor & Subprocessor Risk policy, which now links here as the authoritative source). |
| 0.3 | 2026-08-28 | Sekhar Prakash | Completeness review vs code/IaC: added Temporal, object storage (RustFS/S3), Valkey, docs host; named live LLM providers (Gemini default, OpenAI wired); added a separate "customer-configured integrations (connectors)" section (SAP/Xero/Zoho Books/SharePoint/Salesforce/NetSuite/QuickBooks). ⚠️ inferred rows flagged for operational confirmation. |
| 0.4 | 2026-08-28 | Sekhar Prakash | Confirmed docs host = Cloudflare Pages (not Vercel — nothing on Vercel); resolved that ⚠️ row. |
Finaisse Internal — Confidential. Not for external distribution.