You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
All secrets, API keys, and database credentials must be stored in environment variables, never in source code.
Copy .env.example to .env for local development. The .env file is gitignored and must never be committed.
Reference environment variables through shared/config/config.py — never access os.environ directly in application code.
What Belongs in Environment Variables
Secret
Example Variable
Location
Database connection string
POSTGRES_URI
.env
LLM API key
OPENAI_API_KEY
.env
Langfuse credentials
LANGFUSE_PUBLIC_KEY, LANGFUSE_SECRET_KEY
.env
Redis connection
REDIS_URL
.env
Qdrant connection
QDRANT_URL
.env
Prohibited Practices
No hardcoded secrets, tokens, or credentials in any file committed to the repository.
No secrets in Dockerfiles, docker-compose files, or CI/CD configuration.
No secrets in log output, error messages, or API responses.
No committing .env files or any file containing real credentials.
PII Handling
Data Classification
FinSight may process financial records, employee data, and customer transaction data. Treat all data that can be linked to a natural person as Personally Identifiable Information (PII).
PII Rules
Minimization: Only collect and process PII that is strictly necessary for FP&A operations.
Anonymization: Aggregate or anonymize PII in reports, dashboards, and exported commentary.
Access: PII must only be accessible to authenticated, authorized users. Role-based access control (RBAC) is enforced at the API layer.
Transmission: All data in transit must use TLS 1.2 or higher. Internal service-to-service communication must also be encrypted.
Storage at rest: PII stored in PostgreSQL and Qdrant must reside on encrypted volumes.
Tenant Isolation
FinSight uses a multi-tenant model keyed by tenant_id (e.g., CF001).
All database queries filter by tenant_id. The API layer must validate that the authenticated user has access to the requested tenant.
Vector embeddings in Qdrant must include tenant_id metadata to enforce isolation at query time.
Financial Data Protection
Sensitivity
Financial data (actuals, budgets, forecasts, variances) is classified as highly sensitive. Unauthorized disclosure could impact market position, stock price, or competitive standing.
Protection Measures
Encryption at rest: All financial data in PostgreSQL is stored on encrypted file systems.
Encryption in transit: All API traffic must use HTTPS. Database connections must use TLS.
Access logging: All queries to financial data must be logged with user identity, timestamp, and query scope.
Data masking: API responses may apply data masking for non-privileged users (e.g., hiding specific account-level details).
Monetary Value Handling
All monetary values use decimal.Decimal with sufficient precision to prevent rounding errors that could lead to financial misstatement.
Float types are explicitly rejected at the Pydantic serialization boundary in apps/api/schemas.py.