How we engineer and operate securely
These are the practices we commit to on client engagements. They describe our own controls — they are not a certification claim, and we say plainly where a control is the client's responsibility.
Access and identity
- Least-privilege access to client repositories, cloud accounts and databases, granted per engagement.
- Multi-factor authentication on all engineering and cloud accounts.
- Access reviewed at every milestone and revoked within one business day of a team change.
- Production access separated from development, with break-glass procedures logged.
Data protection
- TLS in transit and encryption at rest for all environments we build.
- Secrets held in a managed secrets store — never in source control or chat.
- Production data is not copied into development; test data is synthetic or masked.
- Regional hosting (EU, UAE and others) available where residency requirements apply.
Secure development
- Peer-reviewed pull requests with automated dependency and secret scanning in CI.
- Threat modelling for money movement, custody, authentication and admin surfaces.
- Immutable audit logging on privileged and financial actions.
- Independent third-party penetration test before production go-live, with retest of findings.
Operations and resilience
- Infrastructure-as-code, reproducible environments and versioned deployments with rollback.
- Monitoring, alerting and on-call rotation for platforms under a support agreement.
- Documented backup and restore procedures, with restore drills rather than untested backups.
- Disaster-recovery objectives agreed with the client and tested before launch.
Incident response
For platforms we operate or support, we triage on a severity scale with defined response targets, keep the client informed in writing throughout, and deliver a written post-incident review with corrective actions. Where notification of regulators or users is required, we support the client’s compliance team with the technical facts and evidence.
Responsible disclosure
If you believe you have found a vulnerability in this website or in a platform we operate, email security@finyantra.tech with steps to reproduce. Please do not access or modify data belonging to others, and give us a reasonable window to remediate before public disclosure. We acknowledge reports within three business days.
What we do not claim
We do not hold ourselves out as certified under SOC 2, ISO 27001 or any similar scheme, and we will never show a certification badge we have not earned. Where a client requires certified attestation, we work with their chosen auditor and implement the controls needed for their programme.