Back to Security

Last Updated: September 11, 2026

Vulnerability Management Policy

Purpose

To find weaknesses in the Finpace platform and its dependencies before they are exploited, and to fix them within a defined time.

Scope

Application code, database schema and access rules, third-party dependencies, and the configuration of hosted infrastructure.

1. Controls in force

  • Automated regression testing on every change. Tests run on every pull request and on every push to the main branch. A failing test blocks the merge. The suite includes a document-fill regression harness that verifies committed form templates continue to produce identical output, so a change to shared code cannot silently corrupt a firm's paperwork.
  • Database-enforced access rules, covering 290 of 290 production tables. Coverage is verified rather than assumed, and a table added without protection is a finding under this policy.
  • Managed platform patching. The database engine and runtime are maintained by the hosting provider, which holds SOC 2 and ISO 27001 certification. Finpace tracks and applies available version upgrades.
  • Least-privilege service credentials. Server-side components hold scoped credentials; client-side code never holds a privileged key.

2. Current state, stated honestly

As of 2026-09-11 Finpace does not run automated third-party dependency scanning, and has not commissioned an external penetration test. Dependency review is manual and occurs at upgrade time. Both are addressed in section 5 with dates. This paragraph will be removed when both are in place, and not before.

3. Remediation timeframes

Severity follows CVSS v3.1 base score, adjusted for exploitability in the Finpace context. A dependency vulnerability in code paths Finpace does not execute may be downgraded, with the reasoning recorded.

  • Critical (9.0 to 10.0): remediate within 72 hours
  • High (7.0 to 8.9): remediate within 7 days
  • Medium (4.0 to 6.9): remediate within 30 days
  • Low (0.1 to 3.9): remediate within 90 days

A vulnerability that cannot be remediated within its window is escalated to the ISMC Chair, who records a compensating control and a revised date. The window is not extended silently.

4. Reporting a vulnerability

Reports are welcome from client firms, their end clients, and independent researchers, at tech@finpace.com. Finpace commits to acknowledge a report within two business days and to provide an assessment within ten.

Finpace will not pursue legal action against a researcher who reports in good faith, acts only against their own account or test data, and does not access, alter or retain another party's client information.

5. Scheduled improvements

  • Automated dependency scanning on every pull request, with alerts on new advisories. Target: Q4 2026.
  • External penetration test of the application and its access rules. Target: with SOC 2 Type II completion.
  • Documented quarterly review of database access-rule coverage. Target: Q4 2026.

6. Review

This policy is reviewed annually by the ISMC, and after any incident that a vulnerability contributed to.