01Security goals
Finger Manager security design focuses on authorized access, role-appropriate data visibility, traceable operations, reduced misuse risk, internal audit support, and standardized operating management.
- Ensure only authorized users access the system
- Ensure roles only view and process data within their responsibilities
- Record and trace key operations
- Reduce account abuse, permission misconfiguration, and data leakage risk
- Support internal audit and operating review
- Help enterprises build more standardized operating workflows
02Account security
Enterprise users should use individual accounts and should not share one account across multiple people. Administrators should regularly review account status.
- Use strong passwords
- Do not share passwords
- Do not store credentials in public environments
- Notify administrators of abnormal login
- Disable accounts promptly after departure or role changes
- Review member lists regularly
- Avoid assigning administrator permissions to unrelated personnel
03Permission control
Finger Manager supports role-based and team-based data access control. Enterprises should follow the least-privilege principle.
- Client profile view permissions
- KYC review permissions
- Payment review permissions
- Risk event view permissions
- Report export permissions
- Operation log view permissions
- Member management permissions
- System configuration permissions
04Roles and data scope
Different members can access different content according to role and data scope. Administrators should configure scope according to internal responsibilities.
- Own tasks only
- Team data
- Specific department data
- Specific region data
- Specific client group data
- Enterprise-wide data
05Audit trails
Finger Manager supports recording key operations for follow-up review, investigation, and internal audit. Audit records help enterprises understand who performed an operation, when it happened, and what result was recorded.
- Login records
- Task handling records
- KYC review records
- Payment review records
- Risk event handling records
- Permission change records
- Report export records
- Client profile change records
- System configuration change records
06Data protection
Finger Manager processes data according to system features and enterprise configuration. Enterprises should also classify and protect data according to business, legal, and internal policy requirements.
- Access permission control
- Transmission security
- Operation log records
- Abnormal access monitoring
- Backup and recovery measures
- Internal permission management
- System security updates
07Mobile security
Finger Manager App improves collaboration efficiency, but mobile use should be paired with device management and account security requirements.
- Enable device passcode or biometrics
- Do not log in on other people's devices
- Avoid processing sensitive tasks on public networks
- Notify administrators promptly if a phone is lost
- Remove access promptly after departure or role changes
- Do not send sensitive screenshots to unrelated channels
08API security
If enterprises use Finger Manager API, API credentials and interface permissions should be managed by authorized technical personnel and should not be transmitted through insecure channels.
- Do not expose API keys in front-end code
- Use different credentials for test and production
- Apply least-privilege API scopes
- Rotate API credentials regularly
- Use IP allowlists
- Verify Webhook signatures
- Record interface call logs
- Monitor abnormal requests
- Disable unused credentials promptly
09Environment management
Finger Manager may support different environments or deployment approaches. Enterprises should avoid using real sensitive data in test environments unless data is desensitized or access is strictly controlled.
- Development environment
- Testing environment
- Pre-production environment
- Production environment
10Report and export security
Reports and exports may contain client information, task records, review results, or other sensitive data. Administrators should review export permissions regularly.
- Restrict report export permissions
- Record export operations
- Control report access scope
- Avoid sending reports to unrelated people
- Store downloaded files properly
- Do not download sensitive reports on public devices
- Do not upload sensitive reports to unapproved third-party services
11Third-party module security
Before enabling third-party modules, enterprises should confirm provider identity, function scope, data access, policies, support model, and fit with internal security requirements.
- Module provider
- Function scope
- Data access permissions
- Privacy Policy
- Terms of Service
- Support model
- Internal security requirements
12Security incident handling
If an enterprise discovers abnormal access, misconfiguration, data export errors, credential exposure, or unauthorized access, it should act promptly and preserve necessary records.
- Suspend related accounts or credentials
- Preserve necessary records
- Notify administrators and responsible people
- Confirm impact scope
- Correct permissions or configuration
- Notify clients or relevant institutions if necessary
- Review and improve internal processes
13Enterprise internal responsibility
Finger Manager provides security tools and management capabilities, but enterprises remain responsible for their own internal management, authorization, data, processes, compliance judgment, integrations, and employee behavior.
- Member authorization
- Permission configuration
- Data entry
- Internal processes
- Compliance judgment
- Legal source of client materials
- Third-party system integration
- Management of downloaded files
- Internal employee behavior management
14Contact security support
If you discover a Finger Manager security issue, abnormal access, data risk, or system vulnerability, contact Sargia Inc.