Security & governance

Controls that follow the decision—not only the database.

Finovant is designed for accountable enterprise workflows. Exact architecture, hosting, access, retention and compliance requirements are confirmed during assessment and contracting.

Control areas

Security, traceability and human review are part of the operating design.

The website describes the intended control approach. Customer-specific commitments apply only when included in an executed agreement, SOW, security schedule or data processing addendum.

Identity and access

Customer-administered invitations, role-based permissions and implementation-scoped identity integration. Public self-registration is not offered.

Workspace boundaries

Customer workspaces and access boundaries are configured according to the agreed deployment and operating model.

Data lineage

Maintain traceability from approved source through transformation, model output, recommendation and decision evidence.

Audit history

Record material alerts, recommendations, approvals, comments, overrides and outcomes for accountable review.

Explainability

Present drivers, assumptions, confidence and supporting evidence so users can review rather than blindly accept an output.

Secrets and connectivity

Connection methods, credentials, key handling and network patterns are defined and reviewed during implementation.

Hosting and resilience

Hosting region, availability approach, backup expectations and recovery requirements are agreed for the customer deployment.

Change control

Material changes to data, logic, integrations and workflows are introduced through an agreed review and release process.

Security review

Customer security, privacy and control requirements are assessed before production use and documented in the SOW or supporting agreements.

Shared responsibility

Secure operation depends on both the platform and the customer operating model.

Exact responsibilities are defined by the contracted deployment. The examples below show the typical separation of duties.

Finovant typically manages

  • Platform and application security controls within the agreed service scope.
  • Workspace configuration, release processes and operational monitoring.
  • Implementation of agreed access roles, workflows and evidence handling.
  • Support for incident, continuity and recovery processes within the service boundary.

Customers typically manage

  • Lawful data use, data ownership and approval of connected sources.
  • User invitations, role assignments and timely removal of access.
  • Source-system security, data quality and customer-managed credentials.
  • Human review, business approvals and the consequences of operating decisions.