Trust & Data Handling

Say what is true. Minimize what we need.

This page describes FinnStack’s current operating boundaries. It is not a certification statement.

Current website controls

  • The public site is static and does not provide a customer-document upload form.
  • The public site does not expose an automated AI processing endpoint.
  • The public site does not use advertising trackers or third-party analytics in the current release.
  • Contact is email-first so scope can be reviewed before work begins.

Engagement principles

  • Ask for only the information needed for the agreed work.
  • Prefer redacted, synthetic or client-side workflows when they can answer the question.
  • Do not claim a security, privacy or regulatory control that has not actually been implemented.
  • Agree any special handling requirements before sensitive material is exchanged.
DORA RoI Rescue pilot: sensitive production RoI data is not currently authorized for intake. Start with public documentation, synthetic examples or fully redacted/non-personal validation errors.

No invented badges.

FinnStack does not claim DORA certification, regulator endorsement, GDPR compliance certification, ISO certification, SOC 2, or other security/compliance credentials unless and until they are actually obtained and applicable.

Questions about a proposed engagement can be discussed before any files are sent.