FintastIQTrust Center
LoginBook a Consultation
Controls

Controls we've adopted

63 of 82 adopted controls are passing their tests. Evidence stays private; auditors review it in a separate, access-controlled view.

As of (just now)

IAM

Identity and access

CodeControlStatusLast testedFrequency
IAM-01Single sign-on for business applications
Workforce access to business applications is authenticated centrally so that sign-in policy, MFA and revocation apply from one identity provider.
Passing(29 d ago)Quarterly
IAM-02Multi-factor authentication
A stolen or guessed password alone is not enough to access any workforce account.
Not passing(7 h ago)Quarterly
IAM-03Password manager
Shared and non-SSO credentials are stored and shared in a controlled vault rather than in documents, chat or browsers.
Passing(29 d ago)Annually
IAM-04Least-privilege access
People and processes hold only the access their role requires, limiting the damage a compromised or misused account can do.
Passing(29 d ago)Quarterly
IAM-05Role-based access control
Permissions are assigned consistently through defined roles so access can be reasoned about, reviewed and revoked as a unit.
Passing(29 d ago)Annually
IAM-06Administrative access restricted
Administrative control over core systems is held by a small, named set of people so that privileged actions are attributable and the attack surface is small.
Passing(29 d ago)Quarterly
IAM-07Access request and approval
No access is provisioned without a recorded business justification and approval from someone accountable for the system.
Not yet tested(29 d ago)Quarterly
IAM-08Password configuration standards
Systems that still rely on passwords resist guessing and reuse attacks.
Passing(7 h ago)Annually
IAM-09Periodic user access review
Access that is no longer needed or was granted in error is found and removed on a regular cycle.
Passing(29 d ago)Quarterly
DATA

Data protection

CodeControlStatusLast testedFrequency
DATA-01Data classification
Everyone handling information knows how sensitive it is and which handling rules apply.
PassingNot yetAnnually
DATA-02Encryption at rest
Confidential data cannot be read from storage media, snapshots or backups by someone who obtains them outside the application.
PassingNot yetQuarterly
DATA-03Encryption in transit
Confidential data cannot be read or altered while it moves across networks.
Passing(7 h ago)Quarterly
DATA-04Data retention schedule
Data is kept only as long as there is a business, contractual or legal reason, reducing exposure from stale records.
PassingNot yetAnnually
DATA-05Secure data disposal
Data that has reached the end of its retention period, or that a subject or customer asks to be deleted, cannot be recovered afterward.
PassingNot yetAnnually
DATA-06Encryption standard and documentation
Encryption is applied consistently with approved algorithms so that weak or outdated cryptography is not introduced.
Not yet testedNot yetAnnually
DATA-12Automated backups
Production data can be recovered after deletion, corruption or loss of a system.
Passing(29 d ago)Quarterly
DATA-13Off-site encrypted backup copies
A regional outage or compromise of the production account does not destroy every copy of production data.
Passing(29 d ago)Quarterly
DATA-14Backup retention
Backups are kept long enough to recover from problems that are discovered late.
Passing(29 d ago)Quarterly
DATA-15Backup restore testing
Backups are proven to be usable within the recovery time and recovery point objectives before they are needed.
PassingNot yetAnnually
CLOUD

Cloud infrastructure

CodeControlStatusLast testedFrequency
CLOUD-01TLS certificates on public endpoints
Public endpoints always present a valid certificate, so users are not exposed to interception or outage from an expired certificate.
Passing(29 d ago)Monthly
CLOUD-02Infrastructure as code
Infrastructure and deployment configuration are reproducible, reviewed and traceable rather than changed by hand.
Passing(29 d ago)Quarterly
CLOUD-03Network firewalls and security groups
Only intended network traffic can reach cloud resources, and administrative ports are not exposed to the internet.
PassingNot yetQuarterly
CLOUD-04Host and container hardening
Compute that FintastIQ manages exposes as little attack surface as possible.
PassingNot yetAnnually
CLOUD-05Managed infrastructure auto-patching
Known vulnerabilities in managed infrastructure are fixed promptly without relying on manual patching.
Not yet testedNot yetQuarterly
CLOUD-06Separate environments
Development and testing activity cannot affect production systems or expose production data.
Passing(29 d ago)Quarterly
PDP

Product delivery

CodeControlStatusLast testedFrequency
PDP-01Agile development process
Product work is planned, prioritized and tracked so that changes are traceable to an agreed purpose.
Passing(4 mo ago)Quarterly
PDP-02Change management process
Production changes are reviewed, tested and approved before release, and can be traced afterward.
Passing(23 d ago)Quarterly
PDP-03Peer review and approval of changes
A second person checks every change before it can reach production, catching errors and unauthorized code.
Not passing(7 h ago)Quarterly
PDP-04Automated testing and CI checks
Changes that break types, tests, lint rules or security checks cannot be merged.
Passing(29 d ago)Quarterly
PDP-05Production deployment access
No individual can place code into production outside the reviewed and gated pipeline.
Passing(29 d ago)Quarterly
PDP-06Source control
All code and infrastructure definitions are versioned, access-controlled and recoverable.
Passing(4 mo ago)Annually
PDP-14Security impact analysis of changes
Significant changes do not weaken security or privacy without someone deciding that knowingly.
Passing(4 mo ago)Annually
APP

Applications

CodeControlStatusLast testedFrequency
APP-01Developer secure coding and encryption guidance
Developers know how to avoid common vulnerabilities and how to use cryptography and secrets correctly.
Passing(4 mo ago)Annually
APP-02Static code analysis
Insecure code patterns are found before and after merge.
Not yet tested(3 mo ago)Monthly
MON

Monitoring and vulnerability management

CodeControlStatusLast testedFrequency
MON-01Centralized logging
Security-relevant logs from every account and system are collected in one protected location so events can be correlated and investigated.
Not yet tested(3 mo ago)Quarterly
MON-02Security event logging
Activity needed to detect and reconstruct security events is captured in every environment.
Passing(4 mo ago)Quarterly
MON-03Security event review
Suspicious activity is noticed and acted on promptly instead of sitting unread in logs.
Not yet tested(3 mo ago)Weekly
MON-04Penetration testing
Exploitable weaknesses in the products and infrastructure are found by an independent tester before an attacker finds them.
Not passing(7 h ago)Annually
MON-05Vulnerability scanning
Known vulnerabilities in cloud workloads, images and dependencies are detected on a regular cadence.
Not yet tested(3 mo ago)Monthly
MON-06Patch management and remediation SLAs
Identified vulnerabilities are fixed within time limits matched to their severity, limiting the window of exposure.
Not yet tested(3 mo ago)Monthly
PEOPLE

People

CodeControlStatusLast testedFrequency
PEOPLE-01Background checks
People given access to customer data have been screened for risks relevant to that trust before they start.
Not yet tested(4 mo ago)Annually
PEOPLE-02Confidentiality agreements
Everyone who handles company or customer information is legally bound to keep it confidential.
PassingNot yetAnnually
PEOPLE-03Termination checklist
Departing personnel lose access and return company property, so no orphaned access or assets remain.
Passing(7 h ago)Quarterly
PEOPLE-04Policy acknowledgment
Personnel know the policies that apply to them and have confirmed they will follow them.
Passing(4 mo ago)Annually
PEOPLE-05Performance reviews
Managers evaluate each person's work at least yearly, including how they meet their security responsibilities.
Passing(29 d ago)Annually
PEOPLE-06Security awareness training
Personnel can recognize and respond to common security threats and know their obligations.
Not passing(7 h ago)Annually
PEOPLE-07Disciplinary and sanctions process
Policy violations have predictable consequences, which deters misconduct and supports fair handling.
PassingNot yetAnnually
PEOPLE-08Job descriptions
Each role's duties, including its security responsibilities, are defined in writing so expectations and access needs are clear.
Not yet testedNot yetAnnually
PEOPLE-09Organizational chart and reporting lines
Reporting lines and decision authority are documented so accountability for security and operations is clear.
PassingNot yetAnnually
PEOPLE-15Code of conduct
Personnel share a written standard for integrity and ethical behavior.
PassingNot yetAnnually
VEND

Vendors

CodeControlStatusLast testedFrequency
VEND-01Vendor inventory
FintastIQ knows every third party it relies on, what data each receives and who is accountable for it.
PassingNot yetAnnually
VEND-02Vendor agreements
Vendors that handle FintastIQ or customer data are contractually bound to protect it.
PassingNot yetAnnually
VEND-03Vendor risk assessment
Risks from a new vendor are understood and accepted before it receives data or access.
PassingNot yetAnnually
VEND-04Vendor monitoring
Changes in a critical vendor's security posture are caught after onboarding, not just at the start.
Not passing(7 h ago)Annually
IT

IT and endpoints

CodeControlStatusLast testedFrequency
IT-01Acceptable use
Personnel know the permitted and prohibited uses of company devices, accounts and tools, including AI tools.
PassingNot yetAnnually
IT-02Workstation disk encryption
Data on a lost or stolen workstation cannot be read.
Not yet testedNot yetQuarterly
IT-03Workstation operating system updates
Workstations run supported operating systems with current security updates.
Not yet tested(7 h ago)Monthly
IT-04Asset inventory
Every company device is accounted for and assigned to a responsible person.
PassingNot yetQuarterly
IT-05System inventory
All systems and applications in use are known, owned and classified so they can be secured and assessed.
PassingNot yetQuarterly
PHYS

Physical security

CodeControlStatusLast testedFrequency
PHYS-01Datacenter physical security
Facilities housing production systems and customer data are physically protected against unauthorized entry.
PassingNot yetAnnually
CUST

Customers

CodeControlStatusLast testedFrequency
CUST-01Customer support channel
Customers can report problems and security concerns through a known channel that is tracked to resolution.
Passing(4 mo ago)Quarterly
CUST-02Master services agreement
Security, confidentiality, availability and data commitments to customers are stated in a binding agreement.
PassingNot yetAnnually
CUST-03Documentation site
Customers have accurate public information about how the system works and what they are responsible for.
PassingNot yetAnnually
CUST-04Release notifications
Customers learn about releases and material changes that affect how they use the service or their security.
Not yet testedNot yetQuarterly
BIZ

Governance and business operations

CodeControlStatusLast testedFrequency
BIZ-01Business continuity and disaster recovery plan
FintastIQ can keep critical services running or restore them within agreed time and data-loss targets after a disruption.
Passing(3 mo ago)Annually
BIZ-02Incident response plan
Security incidents are handled consistently and quickly, limiting damage and meeting notification obligations.
Passing(3 mo ago)Annually
BIZ-03Security incident tracking
Every security incident is recorded and followed to closure, so none is lost and patterns can be analyzed.
Passing(7 h ago)Quarterly
BIZ-04Risk management program
Risks to the business, its information and its clients are identified and treated consistently against a stated appetite.
PassingNot yetAnnually
BIZ-05Risk register
Identified risks stay visible, owned and actively managed between annual assessments.
Passing(4 mo ago)Quarterly
BIZ-06Fraud risk assessment
Opportunities and pressures for fraud are identified so that controls can prevent or detect it.
Passing(4 mo ago)Annually
BIZ-07Control selection
The set of controls in operation is justified by assessed risks and by the requirements of adopted frameworks.
PassingNot yetAnnually
BIZ-08Control reviews
Weaknesses in control design or operation are found within a quarter rather than at audit time.
PassingNot yetQuarterly
BIZ-09Corrective action tracking
Control deficiencies and audit findings are remediated by accountable owners within committed dates.
PassingNot yetQuarterly
BIZ-10Cyber insurance
Financial losses from a cyber incident are transferred in part to an insurer.
Not passingNot yetAnnually
BIZ-11Board of directors oversight
A governing body with independence from day-to-day management holds management accountable for security and compliance.
PassingNot yetAnnually
BIZ-12Board meetings and security reporting
The governing body receives regular, specific information on security, risk and compliance so it can exercise oversight.
PassingNot yetAnnually
BIZ-13Internal support channels
Staff can get IT and security help and report problems through known channels, so issues are raised and handled rather than ignored.
Passing(29 d ago)Annually
BIZ-14Information security program and policy
Leadership sets the direction, scope and objectives of information security in an approved policy that staff must follow.
PassingNot yetAnnually
BIZ-15Security roles and responsibilities
Responsibility and authority for security are clearly assigned, and conflicting duties are separated to reduce the risk of error or abuse.
PassingNot yetAnnually
BIZ-20Business continuity and DR testing
The continuity and recovery plan is proven workable, and gaps are found in a test rather than in a real outage.
PassingNot yetAnnually
BIZ-21Incident response testing
The incident response plan and the people who run it are exercised, so a real incident is handled without improvisation.
Passing(4 mo ago)Annually
LEGAL

Legal and privacy

CodeControlStatusLast testedFrequency
LEGAL-01Privacy policy
Individuals receive an accurate public account of how FintastIQ handles their personal data, avoiding deceptive or incomplete disclosures.
PassingNot yetAnnually