Security

Enterprise-Grade Security

Your data security is our top priority. We implement industry-leading security measures to protect your portfolio and personal information.

Last updated: October 14, 2025

Our Security Commitment
We use the same security standards as banks and financial institutions

Security Measures

TLS Everywhere (HTTPS)

All connections are encrypted with TLS 1.2+ protocol. Your data is protected in transit with the same encryption used by banks.

  • 256-bit SSL/TLS encryption
  • Perfect forward secrecy
  • Automatic certificate renewal
Data Encryption at Rest

All data is encrypted using AES-256 encryption when stored in our databases. Your portfolio content remains private and secure.

  • AES-256 encryption standard
  • Encrypted database backups
  • Secure key management
Access Control & Authentication

Role-based access control ensures only authorized personnel can access your data. Employee accounts require 2FA authentication.

  • Role-based access control (RBAC)
  • Two-factor authentication (2FA)
  • Audit logging for all access
Security Monitoring

Continuous security monitoring with regular vulnerability scans and dependency checks to identify and fix issues proactively.

  • Regular vulnerability scans
  • Automated dependency checks
  • 24/7 security monitoring

Data Protection & Privacy

Data Retention

User accounts are retained until you request deletion. Backups are kept for 90 days for disaster recovery.

No Data Selling

We never sell your personal data. We may use anonymized metrics for product improvement only.

Data Deletion

You can delete your account and all associated data at any time. We permanently remove your information within 30 days.

Compliance Ready

Our security practices are designed to meet GDPR and other data protection requirements.

Responsible Disclosure
Found a security vulnerability? We appreciate your help.

If you discover a security issue, please report it to us at [email protected]

We will acknowledge your report within 48 hours and work with you to resolve the issue promptly.

Questions about our security practices? Contact us