Data Security

Last Updated: January 11, 2025


At Investors Engine, we take the security of your data seriously. This Data Security page outlines the comprehensive measures we implement to protect your personal and financial information from unauthorized access, disclosure, alteration, and destruction.

1. SECURITY OVERVIEW

We employ industry-standard security practices and continuously update our security measures to protect against evolving threats. Our security program is designed to:

  • Ensure the confidentiality, integrity, and availability of user data
  • Protect against anticipated threats or hazards to data security
  • Prevent unauthorized access or use of user data
  • Ensure compliance with applicable data protection regulations

2. DATA ENCRYPTION

2.1 Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3 (Transport Layer Security). This ensures that your information cannot be intercepted or read by unauthorized parties during transmission.

2.2 Encryption at Rest: Sensitive data stored in our databases is encrypted using AES-256 encryption. This includes:

  • User credentials and authentication tokens
  • Personal information
  • Financial data and portfolio information
  • API keys and sensitive configuration data

2.3 Key Management: We use secure key management practices, including:

  • Regular key rotation
  • Secure key storage using hardware security modules (HSMs)
  • Separation of encryption keys from encrypted data
  • Access controls for key management operations

3. ACCESS CONTROLS

3.1 Authentication:

  • Secure password requirements with complexity validation
  • Support for OAuth 2.0 authentication (Google Sign-In)
  • Session management with automatic timeout
  • Protection against brute force attacks through rate limiting

3.2 Authorization:

  • Role-based access control (RBAC) for internal systems
  • Principle of least privilege for all user and system accounts
  • Regular access reviews and privilege audits
  • Multi-factor authentication for administrative access

3.3 Account Security:

  • Email verification for new accounts
  • Secure password reset mechanisms
  • Account lockout policies for suspicious activities
  • Login alerts for new device access (coming soon)

4. INFRASTRUCTURE SECURITY

4.1 Cloud Security: Our infrastructure is hosted on leading cloud platforms that provide:

  • Physical security at data centers
  • Network isolation and segmentation
  • DDoS protection
  • Regular security audits and certifications

4.2 Application Security:

  • Regular security vulnerability assessments
  • Secure coding practices and code reviews
  • Input validation and sanitization
  • Protection against common attacks (SQL injection, XSS, CSRF)
  • Content Security Policy (CSP) headers

4.3 Network Security:

  • Firewall protection with strict ingress/egress rules
  • Network segmentation between application tiers
  • Intrusion detection and prevention systems
  • Regular security monitoring and alerting

5. DATA HANDLING PRACTICES

5.1 Data Minimization: We only collect and retain data that is necessary for providing our services. Unnecessary data is not collected, and retained data is regularly reviewed for continued necessity.

5.2 Data Isolation:

  • User data is logically separated in our databases
  • Multi-tenant architecture with strict data isolation
  • Separate environments for development, testing, and production

5.3 Data Backup and Recovery:

  • Regular automated backups with encryption
  • Geographically distributed backup storage
  • Tested disaster recovery procedures
  • Point-in-time recovery capabilities

6. SECURITY MONITORING

6.1 Continuous Monitoring:

  • 24/7 security monitoring of our infrastructure
  • Real-time threat detection and response
  • Security information and event management (SIEM)
  • Automated alerting for suspicious activities

6.2 Logging and Auditing:

  • Comprehensive logging of security events
  • Secure log storage with tamper protection
  • Regular log analysis and review
  • Audit trails for sensitive operations

7. INCIDENT RESPONSE

7.1 Incident Response Plan: We maintain a comprehensive incident response plan that includes:

  • Clear escalation procedures
  • Defined roles and responsibilities
  • Communication protocols
  • Post-incident review processes

7.2 Data Breach Notification: In the unlikely event of a data breach, we will:

  • Promptly investigate and contain the incident
  • Notify affected users within 72 hours
  • Provide clear information about the impact
  • Offer guidance on protective measures

8. THIRD-PARTY SECURITY

8.1 Vendor Assessment: All third-party services we use undergo security assessment, including:

  • Review of security certifications
  • Data handling agreements
  • Regular security reviews
  • Compliance with our security standards

8.2 Data Processors: We only work with data processors who:

  • Implement appropriate security measures
  • Agree to confidentiality obligations
  • Allow security audits
  • Comply with data protection regulations

9. COMPLIANCE AND CERTIFICATIONS

9.1 Regulatory Compliance: We strive to comply with applicable data protection regulations, including:

  • GDPR (General Data Protection Regulation)
  • CCPA (California Consumer Privacy Act)
  • Industry-specific financial regulations

9.2 Security Standards: We follow industry best practices and standards:

  • OWASP Top 10 security guidelines
  • NIST Cybersecurity Framework
  • ISO 27001 principles (certification planned)

10. USER SECURITY RESPONSIBILITIES

While we implement robust security measures, users also play a crucial role:

10.1 Account Security:

  • Use strong, unique passwords
  • Keep login credentials confidential
  • Enable two-factor authentication (when available)
  • Report suspicious account activity immediately

10.2 Device Security:

  • Keep your devices and browsers updated
  • Use antivirus software
  • Avoid accessing your account on public Wi-Fi
  • Log out when using shared devices

11. SECURITY UPDATES

We continuously improve our security measures. Major security enhancements will be communicated through:

  • Email notifications
  • In-app announcements
  • Updates to this security page

12. REPORTING SECURITY ISSUES

We appreciate security researchers who help us maintain the security of our platform. We commit to:

  • Acknowledging receipt within 48 hours
  • Investigating reported issues promptly
  • Keeping reporters informed of progress
  • Recognizing researchers in our security hall of fame (with permission)

CONTACT US

For questions about our security practices, please contact:

Email: [email protected]

Remember: We will never ask for your password via email or phone. Always verify the authenticity of communications claiming to be from Investors Engine.