Skip to content

Trust and compliance

Finsaku is delivered as a SaaS platform. Finserio operates the platform service, while each customer controls its tenant configuration, users, lending processes, connected providers, and use of customer information.

This section brings the service boundary, supporting evidence, and regulatory control mappings together. Contractual documents remain authoritative for a particular customer, deployment, subscription, or processing arrangement.

Use the right source

Question Source to use
How a user performs a task The applicable Finsaku help article.
How tenant access, workflows, and integrations are configured The Administration guidance and the tenant's current configuration.
Which providers can process information for the service Service providers and subprocessors, followed by the applicable data-processing agreement and current schedule.
Where a contracted deployment stores or processes data Security, hosting, and data location and the applicable service documentation.
How to report or investigate a service incident Service operation and support and the contact route in the agreement.
Whether a control contributes to a regulatory requirement The applicable GDPR, DORA, or related-framework mapping, followed by the organisation's legal and risk assessment.

Shared responsibilities

Finserio is responsible for operating the contracted Finsaku service and the controls assigned to it in the agreement. The customer remains responsible for:

  • approving users, permission groups, affiliations, and privileged access;
  • deciding which customer and lending information to collect;
  • configuring products, decisions, templates, messages, and retention procedures;
  • selecting and governing customer-controlled integrations;
  • establishing lawful processing, lending rules, approvals, and human review;
  • reporting problems through the agreed support and incident channels.

Do not use a help-page statement as evidence of a contractual service level, certification, recovery objective, or processing location. Obtain the current evidence for the contracted environment when those details affect an assessment.

Control layers

Use the regulatory pages to map a requirement to customer-visible Finsaku controls and then identify evidence held outside the platform.

Layer What establishes it
Finsaku product control The current interface, permissions, lending information, audit trail, and configured integrations.
Deployment and service control The applicable service description, data-processing terms, security documentation, recovery commitments, subprocessors, and incident contacts.
Organisation control The customer's policies, lawful basis, approvals, risk assessments, retention schedule, staff training, testing, and regulatory reporting.

Deployment-specific commitments and certifications cannot be inferred from the help site. Request the current evidence and its scope from the service owner or Finserio contact named in the applicable agreement.

Finsaku control areas

Control area Available platform evidence Boundary
Identity and access Unique users, active permission groups, affiliations, OAuth/OIDC sign-in, user status, and permission-controlled impersonation. The customer defines roles, approves access, reviews memberships, and controls the external identity provider where used.
Tenant separation Requests and stored operational data are scoped to the signed-in tenant. Hosting design and deployment assurance belong in the applicable security and service documentation.
Change accountability The audit trail records supported actors, events, times, references, and stored value changes. It is not a security-incident register or a complete regulatory case-management system.
Data collection Administrators configure objects, fields, required values, products, templates, and saved queries. The customer decides what data is necessary, why it is processed, and how long it must be retained.
Data access and export Permissions, affiliations, query visibility, search, and controlled exports restrict and retrieve configured information. A query export is not automatically a complete data-subject or regulatory disclosure package.
External services The integration inventory identifies enabled providers, connection settings, consuming workflows, and provider-specific results. Contracts, credential ownership, processing locations, subprocessors, retention terms, criticality, and exit plans must be maintained outside Finsaku.
Automated work Decisions, event actions, execution history, generated documents, and messages provide operational evidence. A saved rule or completed execution does not prove legal approval, delivery, or a provider-side outcome.
AI access The assistant and MCP server apply signed-in user permissions; the MCP tools have a deliberately limited customer-data boundary. The organisation must approve clients, data use, review rules, and any external AI provider terms.

Regulatory guidance

The authoritative legal texts are the General Data Protection Regulation and the Digital Operational Resilience Act. Use the current text, regulatory guidance, and qualified legal advice for the organisation and jurisdiction being assessed.