Skip to content

Security: Jako0309/FinSight-Assurance

Security

SECURITY.md

Security and Data Boundary

FinSight Assurance is a public hackathon submission that uses synthetic data only.

Data Scope

The repository must not contain:

  • real employee data
  • real finance records
  • customer or supplier data
  • payroll, tax, banking, or contract data
  • student records or resumes
  • API keys, credentials, secrets, tokens, or connection strings
  • Azure subscription IDs, tenant IDs, billing pages, or account screenshots

Secret Handling

The local tool API can run without an API key for review. Reviewers do not need to provide their own API key to run the repository.

If a hosted endpoint is deployed, configure FINSIGHT_TOOL_API_KEY as a project-side platform environment variable and do not commit it.

Do not place secrets in:

  • .env files committed to Git
  • README or documentation
  • screenshots
  • Foundry validation reports
  • issue comments
  • public project descriptions

Reporting a Concern

If a reviewer finds real personal data, confidential data, credentials, or an unsafe claim in the repository, remove the public submission artifact and replace it with a synthetic-only version before continuing the demo.

Product Boundary

FinSight Assurance does not provide final accounting advice and does not replace finance managers. AI-assisted reporting output remains draft material until source data, privacy handling, and manager approval are reviewed.

There aren't any published security advisories