Privacy & Policies FinovatePro Access Controls Policy

FinovatePro Access Controls Policy

Version 1.1 — Approved by Executive Management
Effective Date: November 1, 2025

  1. Purpose

This Access Controls Policy establishes the administrative, technical, and physical controls used by FinovatePro to protect access to systems, cloud infrastructure, applications, and sensitive customer data—including financial data accessed via Plaid.
Its purpose is to ensure that access is authorized, limited, monitored, and compliant with industry standards and Plaid’s security requirements.

  1. Scope

This policy applies to:

  • All FinovatePro employees, contractors, and authorized third parties
  • All production, staging, and development environments
  • All systems, APIs, cloud resources, and databases
  • All customer and financial data processed or stored by FinovatePro

This policy governs both human and non-human (machine/API) access.

  1. Policy Governance

The information security governance structure includes:

Executive Owner

CEO & Chief Strategist — Overall accountability for the security program and approval of access-related policies.

Information Security & Compliance Manager

Responsible for operational oversight of access controls, enforcement, reviews, and compliance monitoring.

Technical Security Lead

Manages identity and access management (IAM), cloud infrastructure controls, encryption, and audit logging.

This policy is reviewed annually or upon material changes.

  1. Access Control Principles

4.1 Least Privilege

All access is provisioned based strictly on least privilege and the minimum rights necessary to perform job duties.

4.2 Role-Based Access Control (RBAC)

Permissions are defined by roles, documented, and approved by management.
RBAC is enforced across all FinovatePro environments.

4.3 Zero Trust Access Model

FinovatePro applies Zero Trust principles:

  • Continuous authentication
  • No implicit trust for networks, devices, or users
  • MFA enforced for all privileged access
  • Context-aware access validations

4.4 Segregation of Duties

Administrative privileges and critical duties (e.g., code deploy, environment changes) require separation of roles to avoid conflicts of interest and minimize insider risk.

  1. Authentication Requirements

5.1 Multi-Factor Authentication (MFA)

Mandatory for:

  • All administrative, engineering, and production access
  • Access to cloud environments and management consoles
  • Any privileged system or database access

5.2 Password and Credential Requirements

  • Passwords must meet complexity requirements
  • Password reuse is prohibited
  • Passwords are never transmitted or stored in plain text
  • Credentials are rotated based on policy and risk level

5.3 Non-Human Authentication

All system-to-system access uses:

  • OAuth tokens
  • Scoped API keys
  • TLS certificates
  • Encrypted secret management

Secrets must be stored in:

  • Cloud-native encrypted vaults (e.g., AWS Secrets Manager)

Plain-text secrets storage is strictly prohibited.

  1. Authorization Controls

6.1 Access Approvals

All access requests require:

  • Documented business justification
  • Approval from Security Lead or System Owner
  • Logging of approved permissions

6.2 Privileged Access Management

Privileged access is tightly restricted and monitored.
Admin privileges are granted only to authorized personnel with explicit approval.

6.3 Environmental Access Controls

  • Production data is never accessed without documented authorization
  • Engineers cannot access production credentials without approval
  • Sensitive data is masked in lower environments
  1. Provisioning & De-Provisioning

7.1 Access Provisioning Process

New access is granted only after:

  • Identity verification
  • Role justification
  • Manager approval
  • Security team validation

7.2 Immediate De-Provisioning

Upon termination or role change:

  • All access is removed immediately
  • Automated IAM rules disable accounts
  • Manual verification is performed within 24 hours

This supports Plaid’s “timely revocation” requirement.

  1. Periodic Access Reviews

FinovatePro conducts quarterly access reviews of:

  • User accounts
  • Permissions and roles
  • Privileged accounts
  • Third-party and service accounts
  • Access to Plaid-derived data

Findings are documented, remediated, and reviewed by management.

  1. Logging, Monitoring & Audit Trails

FinovatePro maintains centralized logging of:

  • Access requests
  • Authentication events
  • Privileged actions
  • System changes
  • API access

Monitoring includes anomaly detection and alerting.
Logs are retained for at least 12 months for compliance.

  1. Third-Party Access Controls

Vendors and contractors must:

  • Undergo security review
  • Receive the minimum necessary access
  • Have temporary or time-bound permissions
  • Be monitored and audited regularly

No third party may access Plaid-derived data without explicit approval.

  1. Physical & Cloud Access Controls
  • All production systems are hosted in SOC 2 / ISO 27001 certified cloud environments
  • Physical access controls are provided by the cloud provider
  • No customer data is stored on local devices
  • All devices accessing systems must meet baseline security requirements (MFA, encryption, patching)
  1. Enforcement

Violations of this policy may result in:

  • Immediate removal of access
  • Disciplinary action
  • Contract termination
  • Escalation to executive leadership
  1. Policy Review & Maintenance

This policy is reviewed annually and updated as needed to reflect:

  • Regulatory requirements
  • Plaid security standards
  • Industry best practices
  • Internal risk assessments

Need Help?

If you have questions about this policy, our security practices, or how your information is handled, please contact the FinovatePro team.

Scroll to Top