Security policies

These policies describe the operational security controls FinArctic LLC and its platform licensor, Fluent Terrain LLC, use for GlacialBooks. They are public so customers and integration partners can review how financial data is protected.

Information Security Policy

Severity deadlines, vulnerability remediation targets, incident response timing, and annual review requirements.

Read policy
Access Controls Policy

Identity, workforce MFA, RBAC, least privilege, access review requirements, and non-human access rules for production systems.

Read policy
Data Retention and Deletion Policy

The authoritative retention schedule, including 30-day account deletion grace, 7-year accounting retention, backups, logs, and legal holds.

Read policy
Account Authentication

Consumer and workforce multi factor authentication requirements, including the control that gates Plaid Link.

Read policy
Data Processing Addendum

Customer processor terms, security measures, subprocessors, incident duties, deletion, audit rights, and international transfer safeguards.

Read policy
AI Transparency and Risk Management

Production automation methods, data-use and model-training boundaries, known limitations, oversight, and correction controls.

Read policy