generated: '2026-07-25' method: searched source: https://www.finaeo.com/security/ source_note: Finaeo Security Statement, last updated 2021-07-26. Live host returns HTTP 403 (Cloudflare bot challenge); content read in full via Internet Archive. note: | Finaeo publishes no machine-readable API contract, so none of the API-level cross-cutting standards below can be asserted — they are recorded as not-conformed on the evidence of absence, not assumed. The one substantive standards surface Finaeo does publish is its Security Statement, which describes an internal security program (OWASP Top 10 testing, monthly vulnerability scanning, annual third-party penetration testing) and inherits data-centre certifications from AWS. IMPORTANT DISTINCTION, recorded because it is easy to misread: the certification list on that page (PCI DSS Level 1, ISO 27001, FISMA Moderate, FedRAMP, HIPAA, SOC 1 & SOC 2) is explicitly attributed to AWS as Finaeo's hosting provider — "AWS maintains annual certifications and 3rd party audit reports including..." Those are inherited infrastructure certifications, NOT Finaeo certifications. Finaeo's own SOC 2 is stated only as an intention: "Starting in 2022-Q1, Finaeo plans to complete SOC-2 security reviews for its platform, and intends to perform these annually on an ongoing basis." No completed Finaeo audit report, certificate, or trust portal was found, and the page has not been updated since 2021-07-26. (The same paragraph also carries an uncorrected copy-paste error, describing how "Rock Content achieves key compliance controls" — a third-party template left in place.) Because no Finaeo-held certification is published, this repo emits no Compliance and no TrustCenter pointer. standards: - id: openapi conforms: false evidence: no OpenAPI/Swagger document published or discoverable on any host - id: asyncapi conforms: false evidence: no event, streaming or webhook surface documented - id: graphql conforms: false evidence: no GraphQL endpoint documented or discoverable - id: oauth2 conforms: false evidence: no OAuth 2.0 surface; /.well-known/oauth-authorization-server not served - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 from origin in archived captures (2023-10-11, 2023-12-13) - id: rfc9116-security-txt conforms: false evidence: no /.well-known/security.txt published - id: rfc9457-problem-details conforms: false evidence: no public API to evaluate - id: acord-al3 conforms: false evidence: zero ACORD/AL3/ACORD-XML/NGDS/IVANS references across 2,840 archived first-party URLs; Finaeo is a life-side distribution platform outside the P&C agency-download rails - id: owasp-top-10 conforms: true evidence: 'Security Statement: "Monthly vulnerability testing and annual independent, manual penetration testing are performed to check for OWASP Top 10 security risks."' - id: soc2 conforms: false status: planned-not-evidenced evidence: 'Security Statement (2021-07-26): "Starting in 2022-Q1, Finaeo plans to complete SOC-2 security reviews for its platform." No completed report, certificate or trust portal published; page not updated since.' - id: iso-27001 conforms: inherited evidence: attributed to AWS data centres, not to Finaeo - id: pci-dss conforms: inherited evidence: AWS PCI DSS Level 1 cited as a hosting-provider certification - id: hipaa conforms: inherited evidence: AWS HIPAA cited as a hosting-provider attestation; Finaeo is a Canadian life-insurance distribution platform, not a US covered entity - id: fedramp conforms: inherited evidence: AWS FedRAMP cited as a hosting-provider authorization security_program: hosting: AWS (VPC, ECS on EC2, ELB, encrypted RDS in private subnets, multi-AZ) regions: [AWS Canada, 'AWS US (stated as "coming soon" in 2021")'] encryption: databases encrypted at rest; backups encrypted in storage and transit; CloudWatch logs AES-256 in transit and at rest monitoring: [New Relic, AWS CloudWatch, AWS GuardDuty, AWS Shield, host-based IDS, file integrity monitoring] vulnerability_testing: monthly penetration_testing: annual, independent, manual dependency_scanning: third-party libraries scanned for outdated/insecure versions access_control: MFA + VPN allowlist to servers/databases; role-based least privilege; quarterly access reviews bcdr: business continuity and disaster recovery tested and reviewed annually; terraform + CI/CD redeploy; daily backups retained ≥7 days training: security and privacy training at onboarding and annually disclosure_program: none published — no security.txt, no security@ contact, no bug bounty, no responsible-disclosure page