Skip to content
Last updated: Sep 25, 2026

ISMS Scope & Framework ​

OwnerClassificationVersionEffectiveNext reviewStatus
Security & Infrastructure Owner (Sekhar) · Approved by COO (Payeli)Internal0.12026-08-272026-11-27Draft

Purpose. The front door to the Finaisse Information Security Management System (ISMS). It defines the ISMS scope, objectives, governance, and the map to the policies, controls, and records that make up the system. An auditor starts here.

1. ISMS scope ​

The ISMS covers the security of the Finaisse multi-tenant financial platform and the information entrusted to it:

  • Systems — the blitz backend microservices, blitz-ui frontend, and fin-infra infrastructure-as-code.
  • Environments — staging (Railway, live) and production (AWS ap-south-1, in build).
  • Data — all customer financial data and PII (Restricted), and the internal data supporting the platform.
  • People — all Finaisse personnel and contractors, and the subprocessors that process its data.

Boundaries and exclusions are recorded in the Statement of Applicability.

2. Objectives ​

  • Protect the confidentiality, integrity, and availability of customer financial data.
  • Enforce tenant isolation — no customer can reach another's data, workload, or identity.
  • Achieve SOC 2 Type II attestation; maintain India DPDP baseline; pursue ISO 27001 and ISO 42001 as demand warrants.
  • Drive the findings gap list to closure before the first production tenant.

Measurable targets are tracked via the posture dashboard and programme history.

3. Governance & leadership ​

RoleResponsibilityHolder
Executive sponsor / ApproverApproves the ISMS, policies, and risk posture; demonstrates management commitmentCOO (Payeli)
ISMS ownerOwns and operates the ISMS, chairs reviewsSecurity & Infrastructure Owner (Sekhar)
Policy ownersOwn individual policies per functionSee Policy Library
EngineeringImplements and evidences controlsAll engineers

4. The ISMS map ​

ComponentLocation
CharterInformation Security Policy
Policy library/policies/
Risk processRisk Management Policy → Risk Register
Control setControl Register · Domains
ApplicabilityStatement of Applicability
Evidence & assessmentEvidence Register · Audit & Assessment Log
Programme historyProgramme History

5. ISMS Policies ​

The 18 policies that govern this ISMS live in the ISMS Policy Library — each mapped to the SOC 2 trust services criteria it satisfies, with an owner and a revision history. Start there for the governing rules; this page is the map, not the ruleset itself.

6. ISO-mandatory documents (status) ​

Required for ISO 27001 certification (not for SOC 2):

DocumentStatus
ISMS scope statement🟠 this page
Security objectives🟠 §2 above; formalise on ISO pursuit
Risk assessment methodology✅ Risk Management Policy
Statement of Applicability✅ SoA
Internal audit programme🔴 placeholder
Management review records🔴 placeholder

Revision history ​

VersionDateAuthorChange
0.12026-08-27Security & Infrastructure OwnerInitial ISMS scope and framework.
0.22026-09-07Security & Infrastructure OwnerAdded §5 (ISMS Policies), a dedicated section pointing to the Policy Library; renumbered the ISO-mandatory documents section to §6.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.