Last Updated: September 11, 2026
Incident Response Plan
Purpose
To identify, contain, remediate and report security events affecting the confidentiality, integrity or availability of client information, and to meet the notification obligations that Finpace's client firms carry under Regulation S-P.
Scope
Any actual or suspected unauthorised access to, disclosure of, alteration of, or loss of client information held by Finpace, and any material disruption to the service.
1. Roles
- ISMC Chair (Forrest Tuten, team@finpace.com): Declares an incident, owns severity and the decision to notify.
- Information Security Manager (tech@finpace.com): Technical investigation, containment, evidence preservation.
- Client communications (ISMC Chair): Written notice to affected firms, and all follow-on updates.
Where one person holds more than one role, the responsibilities still apply separately, and every decision is recorded with a timestamp.
2. Severity
- Sev 1: Confirmed unauthorised access to client information, or confirmed exposure of client data across firm boundaries. Response begins immediately, at any hour.
- Sev 2: Credible suspicion of the above; or loss of integrity in client records; or total service unavailability. Response begins within 4 hours.
- Sev 3: A vulnerability or control failure with no evidence of exploitation. Response begins the next business day.
3. Detection
Finpace becomes aware of events through:
- The audit trail. Every change to a client record is written with the acting identity and a timestamp. The trail held 41,340 recorded events as of 2026-09-11. Audit records deliberately outlive the rows they describe, so deleting a record does not delete its history.
- Platform alerting from the hosting provider, covering availability and database health.
- Reports from client firms or their end clients, to team@finpace.com or through any support channel.
- Reports from security researchers, under the Vulnerability Management Policy.
4. Response
- Declare and assign. The ISMC Chair declares the incident, assigns severity, and names the responder. The clock for notification starts at the moment of awareness, not at the moment of confirmation.
- Contain. Revoke affected credentials and share links, disable the affected path, or take the service offline if containment requires it. Containment takes precedence over preserving availability.
- Preserve evidence. Capture audit records, application logs and database state before remediating. Remediation must not destroy the record of what happened.
- Assess scope. Determine which firms and which end clients are affected, which data categories were reachable, and over what window.
- Notify. Per section 5.
- Eradicate and recover. Remove the cause, restore service, and verify the fix in production.
- Review. Per section 6.
5. Notification
Finpace will give written notice to the designated compliance contact at each affected firm within 72 hours of becoming aware of unauthorised access to that firm's client information. The notice states what is known at the time of writing: the data categories involved, the firms and end clients affected where known, the time window, the containment steps taken, and what remains under investigation.
Finpace issues an initial notice within the deadline and updates it as the assessment develops, rather than withholding notice until the picture is complete.
Finpace will cooperate with each affected firm's own regulatory notification obligations, including providing audit records and a written account suitable for submission to a regulator.
6. Post-incident review
Every Sev 1 and Sev 2 incident receives a written review within ten business days, covering the timeline, the root cause, why existing controls did not prevent it, and the specific changes made. Reviews are retained and are available to client firms on request.
7. Testing
This plan is exercised at least annually, in conjunction with the business continuity testing owned by the ISMC. The exercise result is recorded, and the plan is updated where the exercise finds a gap. The first exercise is anticipated on or before 1 March 2027.