Security Policy
Last Updated: May 12, 2025
Fynfinitex ("we," "us," or "our") is committed to protecting the security, integrity, and confidentiality of all data processed through our platform at fynfinitex.com. This Security Policy describes the technical and organizational measures we implement to safeguard our systems and your information.
1. Scope
This policy applies to all systems, infrastructure, applications, and services operated by Fynfinitex, including our web platform, APIs, internal tools, and any third-party integrations used in the delivery of our services. It applies to all personnel, contractors, and authorized users who access or interact with our systems.
2. Information Security Principles
Our security program is guided by the following core principles:
Confidentiality: Access to data is restricted to authorized individuals only, based on the principle of least privilege.
Integrity: We implement controls to ensure that data is accurate, complete, and protected against unauthorized modification.
Availability: We design our systems to be resilient and maintain service continuity through redundancy, monitoring, and incident response procedures.
3. Infrastructure Security
3.1 Hosting and Environment
Our services are hosted on industry-standard cloud infrastructure. We select infrastructure providers that maintain recognized security certifications and compliance frameworks. Physical access to underlying hardware is controlled by our infrastructure providers under their respective security programs.
3.2 Network Security
We implement network-level controls including firewalls, intrusion detection systems, and traffic filtering. Network access is segmented to limit lateral movement in the event of a security incident. All external-facing services are protected against common network-layer threats.
3.3 System Hardening
All systems are configured according to security hardening baselines. Unnecessary services, ports, and protocols are disabled. Operating systems and software components are kept up to date with security patches applied on a regular schedule.
4. Data Security
4.1 Encryption in Transit
All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS). We enforce current TLS versions and disable deprecated cipher suites. Connections over unencrypted protocols are not permitted for sensitive data exchange.
4.2 Encryption at Rest
Sensitive data stored within our systems is encrypted at rest using industry-standard encryption algorithms. Encryption keys are managed through secure key management practices, including separation of keys from encrypted data and periodic key rotation.
4.3 Data Minimization
We collect and retain only the data necessary to provide our services. Data that is no longer required is securely deleted or anonymized in accordance with our data retention practices.
5. Access Control
5.1 Authentication
Access to internal systems requires strong authentication. We enforce multi-factor authentication (MFA) for all personnel accessing production environments and administrative interfaces. Password policies require minimum complexity standards and regular rotation where applicable.
5.2 Authorization and Least Privilege
Access rights are granted based on job function and the principle of least privilege. Users and systems are granted only the permissions necessary to perform their designated tasks. Access rights are reviewed periodically and revoked promptly upon role change or termination.
5.3 Administrative Access
Administrative access to production systems is strictly controlled, logged, and audited. Direct database access is restricted and monitored. All privileged sessions are subject to enhanced logging and review.
6. Application Security
6.1 Secure Development Practices
Our development process incorporates security at every stage. Developers follow secure coding guidelines, and code changes undergo review before deployment. Security considerations are integrated into design, development, testing, and release phases.
6.2 Vulnerability Management
We conduct regular vulnerability assessments of our applications and infrastructure. Identified vulnerabilities are prioritized based on risk severity and remediated within defined timeframes. Critical vulnerabilities are addressed on an expedited basis.
6.3 Dependency Management
Third-party libraries and dependencies are tracked and monitored for known vulnerabilities. We apply updates and patches to address security issues in dependencies as they are disclosed.
6.4 Security Testing
We perform periodic security testing including penetration testing of our platform. Findings from security assessments are reviewed, prioritized, and addressed through our vulnerability management process.
7. Monitoring and Logging
Our systems are monitored continuously for security events, anomalies, and performance indicators. Security-relevant events are logged and retained for a defined period to support incident investigation and audit purposes. Automated alerting notifies our security team of suspicious activity in real time.
Logs are protected against unauthorized modification and access. Log integrity is maintained to ensure their reliability as an audit trail.
8. Incident Response
8.1 Incident Detection and Classification
We maintain an incident response process to detect, classify, contain, and resolve security incidents. Incidents are categorized by severity to ensure proportionate and timely response.
8.2 Containment and Recovery
Upon identification of a security incident, our team takes immediate steps to contain the impact, preserve evidence, and restore affected systems to a secure state. Root cause analysis is conducted following resolution to prevent recurrence.
8.3 Notification
In the event of a security incident that affects user data, we will notify impacted users in a timely manner in accordance with applicable obligations. Notifications will include a description of the incident, the data involved, and steps users can take to protect themselves.
9. Business Continuity and Disaster Recovery
We maintain business continuity and disaster recovery plans to ensure service availability in the event of significant disruptions. Our systems are designed with redundancy to minimize single points of failure. Recovery procedures are tested periodically to validate their effectiveness.
Data backups are performed on a regular schedule. Backups are encrypted and stored in a manner that supports recovery in the event of data loss or system failure.
10. Third-Party and Vendor Security
We evaluate the security posture of third-party vendors and service providers before engagement. Vendors with access to our systems or data are required to maintain appropriate security standards. We review vendor security practices periodically and include security requirements in contractual agreements where applicable.
11. Personnel Security
All personnel with access to systems or data undergo security awareness training. Training covers topics including phishing recognition, secure handling of credentials, data protection responsibilities, and incident reporting procedures. Security awareness is reinforced through ongoing communications and periodic refresher training.
Personnel are required to acknowledge and comply with our internal security policies as a condition of access. Access is revoked promptly upon departure or role change.
12. Physical Security
Our offices and internal workstations are subject to physical access controls. Employees are required to use screen locks and secure workstations when unattended. Physical media containing sensitive data is handled and disposed of securely.
Physical security of underlying cloud infrastructure is the responsibility of our infrastructure providers, who maintain their own physical security controls and certifications.
13. Compliance and Audit
We periodically review our security controls and practices to assess their effectiveness and alignment with current standards. Internal audits and assessments are conducted to identify gaps and drive continuous improvement. We maintain documentation of our security program to support accountability and transparency.
14. Responsible Disclosure
We welcome reports of potential security vulnerabilities from security researchers and users. If you believe you have identified a security issue affecting our platform, please contact us promptly at the address below. We are committed to investigating all credible reports and working to resolve confirmed issues in a timely manner.
We ask that you act in good faith, avoid accessing or modifying data that does not belong to you, and refrain from publicly disclosing the issue until we have had a reasonable opportunity to investigate and remediate.
15. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically to stay informed about our security practices.
16. Contact Us
If you have questions about this Security Policy or wish to report a security concern, please contact us:
Fynfinitex
404 Hand Ave, Cape May Court House, NJ 08210, United States
Email: [email protected]
Phone: +1 (914) 440-0113
Website: fynfinitex.com