Skip to content
Last updated: Sep 25, 2026

Security Posture ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal1.62026-06-242026-11-27Active

Purpose. A live snapshot of the current security posture for the Finaisse platform (multi-tenant financial SaaS). Established at iteration 1 (2026-06-24); last re-verified 2026-09-10; reviewed quarterly and on major architecture change.

At a glance ​

EnvironmentsTarget framework
Staging on Railway (live) · Production on AWS ap-south-1 (in build)SOC 2 (target) · India DPDP baseline · ISO 27001 likely

Pre-production hardening in progress

  • 0 of 20 domains at target state — 10 critical, 10 partial.
  • 4 P0 findings block production go-live — down from 8: tenant binding (F-01), both SQL injections (F-03, F-39) and password hashing (F-40) were fixed and verified in the 2026-09-04 → 09-09 window.
  • More findings = the posture working: dev security review surfaces real issues before the first production tenant.
  • Latest pass + full history → Audit & Assessment Log · what's been assessed → Coverage.

Status by area ​

Each area's current status; drill into its detail page.

AreaStatusDetail
Findings4 P0 · 12 P1 · 12 P2 · 5 P3 open · 7 resolved · 1 risk-acceptedFindings Register
Domain maturity0 🟢 · 11 🟠 · 9 🔴 (of 20)Security Domains
Assessment coverage5 of 9 lenses run (owned by Coverage)Coverage & Methodology
Controls & frameworksSOC 2 Type II in prep · SOC 1 Type 2 required (STP)Framework & Cert Register
Data & privacyRoPA · data-flows · subprocessors — in progressData & Privacy
AI governanceTokenisation designed · DPIA + no-train endpoint pendingAI Governance
Production go-live🔴 blocked — 4 P0 + detection baseline gapsAWS Production Gate

All findings carry the security label and sit on the Finboard project.

The 4 P0 blockers — must clear before production:

FindingBlocker
F-04Permissive CORS (origin: () => true + credentials), including admin apimgmt
F-25Mass-assignment — 39 Tier-1 routes + 2 approval writes with no trusted actor (runtime scan, 2026-09-23; Tier 2 split to F-54)
F-26Arbitrary-field filtering (BOLA) — surface moved, hole not closed
F-41No brute-force / lockout protection on signin

Cleared in the 2026-09-04 → 09-09 window: F-01 tenant binding · F-03 and F-39 SQL injection · F-40 password hashing (now argon2id). See the Findings Register for the verified fix detail.

7 owner decisions pending — tooling, vendor & scope calls → Open Decisions.

Domain maturity — 20 domains ​

🔴 critical gaps · 🟠 partial · 🟢 healthy · 0 🟢 / 11 🟠 / 9 🔴 (D7 Tenant Isolation 🔴→🟠 — binding landed 2026-09-04; RLS backstop and the CI cross-tenant test remain. D18 Vendor Risk 🔴→🟠 2026-09-15 — the Subprocessor Register exists; DPAs/attestations still unrecorded)

Red domains (9): 1 Governance · 4 IAM · 5 AppSec · 6 API · 10 Container & Runtime · 15 Compliance · 16 Financial Data Integrity · 19 Endpoint · 20 People

The remaining 11 are 🟠. Per-domain scores and their rationale live in Security Domains — that page owns them; this one shows the tally. The full 20-row table used to be duplicated here, which meant every score change had to be made in two places and the two drifted.

Go-live gate ​

Production is gated on must-have controls plus the application P0s above.

GateStatus
App blockers (tenant isolation, RBAC, SQLi, CORS, MFA, auth hardening)🟠 improving — RBAC enforced (F-02 ✅), tenant binding (F-01 ✅), both SQLi (F-03, F-39 ✅), password hashing (F-40 ✅). 4 P0s remain: CORS (F-04), mass-assignment (F-25), BOLA filter (F-26), signin throttling (F-41). RLS backstop still outstanding
Detection baseline (CloudTrail, GuardDuty, Security Hub, VPC Flow Logs)🟠 partial — GuardDuty + Flow Logs in; CloudTrail + Security Hub still out
Edge (WAF, ALB + TLS, HTTPS-only)🟢 ALB + ACM TLS + 80→443 + WAF in (F-13 ✅)
IAM least-privilege + KMS CMKs🟠 partial — CMKs + Identity Center in; IAM wildcards remain
Independent validation (penetration test)🔴 not started

Full gate: AWS Production Security Gate → · AWS-native options for the open Part B items: Options Assessment → · broader AWS service research: Service Reference →

Access & handling

Restricted to members of the finaisse-org GitHub organization (Cloudflare Access, GitHub org-membership policy) — the same audience that can read the private repos and issues, and for the same reason: both authorise on org membership. Internal-confidential: do not share findings, issue links, or screenshots outside Finaisse. Exploit detail lives in the linked issues, not on this site.

Revision history ​

VersionDateAuthorChange
1.02026-06-24Sekhar PrakashIteration-1 posture established (20 domains, initial findings).
1.12026-07-10Sekhar PrakashRe-verification against main; F-13 (ALB/TLS) resolved.
1.22026-07-18Sekhar PrakashF-36 resolved (lockfile guard); F-37 raised.
1.32026-08-06Sekhar PrakashF-02 (backend RBAC) resolved; F-38 raised.
1.42026-08-26Sekhar PrakashF-39–F-41 raised; P0 count 5→8.
1.52026-08-27Sekhar PrakashRestructured to the Scoreboard template (At a glance · Status summary · Domain maturity · Go-live gate).
1.62026-09-10Sekhar PrakashReconciled to live issue state: P0 8→4 (F-01, F-03, F-39, F-40 verified fixed); counts, cards, blocker table and go-live gate updated; P3 tier reflected.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.