Trust & Data Handling
Say what is true. Minimize what we need.
This page describes FinnStack’s current operating boundaries. It is not a certification statement.
Current website controls
- The public site is static and does not provide a customer-document upload form.
- The public site does not expose an automated AI processing endpoint.
- The public site does not use advertising trackers or third-party analytics in the current release.
- Contact is email-first so scope can be reviewed before work begins.
Engagement principles
- Ask for only the information needed for the agreed work.
- Prefer redacted, synthetic or client-side workflows when they can answer the question.
- Do not claim a security, privacy or regulatory control that has not actually been implemented.
- Agree any special handling requirements before sensitive material is exchanged.
DORA RoI Rescue pilot: sensitive production RoI data is not currently authorized for intake. Start with public documentation, synthetic examples or fully redacted/non-personal validation errors.
No invented badges.
FinnStack does not claim DORA certification, regulator endorsement, GDPR compliance certification, ISO certification, SOC 2, or other security/compliance credentials unless and until they are actually obtained and applicable.
Questions about a proposed engagement can be discussed before any files are sent.
