Security, hosting, and data location
Finsaku is a hosted SaaS platform. Security depends on both the operated service and the way each customer configures identities, permissions, collected information, products, and external providers.
This page describes the standard technical boundary without replacing a security schedule, architecture pack, penetration-test report, or customer-specific agreement.
Standard hosting boundary
The standard deployment configuration places the main application, database, file storage, and supporting workloads in Amazon Web Services. The current standard infrastructure region is eu-west-1. Managed Elastic logging and performance-monitoring resources are also configured in eu-west-1.
A custom deployment, custom domain, identity provider, or customer-controlled integration can introduce different processing locations. Confirm the complete location set from the applicable agreement and provider records before completing a transfer or residency assessment.
Platform controls
| Area | Finsaku control | Customer action |
|---|---|---|
| Authentication | The platform supports OAuth/OIDC-based authentication and deployment-specific identity configuration. | Govern the identity provider, authentication policy, recovery process, and privileged accounts. |
| Authorisation | Permissions, active groups, tenant scope, affiliations, and user status control application operations. | Design roles, review cumulative access, test negative access, and block leavers or compromised accounts. |
| Tenant boundary | Signed-in requests and stored operational information are scoped to the tenant context. | Do not share users or credentials, and test partner and integration identities against out-of-scope information. |
| Auditability | Audit history records supported actors, events, times, references, and stored changes. Event-action history records workflow execution. | Restrict audit access, preserve required evidence, and correlate platform history with identity-provider, infrastructure, and provider evidence. |
| File storage | The standard file-storage configuration uses encrypted storage and rejects non-secure storage transport. | Control which documents are uploaded, who can retrieve them, and how exported copies are handled. |
| Network and database boundary | The standard database is not publicly accessible. Platform workloads and managed services use deployment-controlled networking. | Govern customer endpoints, custom domains, allowlists, connected systems, and administrator devices. |
| Integration secrets | Integration credentials are stored as protected configuration and are not returned through normal provider-availability checks. | Limit integration-administration permission, use environment-specific credentials, rotate them, and never place secrets in templates, screenshots, notes, or support messages. |
| AI access | The in-app assistant and MCP server apply the signed-in user's Finsaku permissions. | Approve AI use, restrict permissions, review external client and model terms, and verify generated answers or changes. |
Obtain deployment evidence
Ask the service owner for the evidence required by the assessment. Depending on scope, this can include:
- current architecture and data-flow diagrams;
- processing and backup locations;
- encryption and key-management descriptions;
- vulnerability-management and independent test evidence;
- availability, monitoring, backup, restoration, and recovery commitments;
- privileged-access and support-access controls;
- incident contacts and notification terms;
- certifications and reports with their exact service and period scope.
Do not infer a certification, recovery objective, or security guarantee from the presence of an application control. See Service operation and support for incident and restoration procedures.