Security

Your brokerage data, handled like our own.

Read-only access. Encrypted everywhere. Questions? Email security@wealthflows.app.

Read-only brokerage access

We connect via SnapTrade and broker OAuth. WealthFlows can see positions and transactions; we can never place trades, move money, or reset passwords. Your credentials never touch our servers.

TLS 1.3 in transit

Every request — browser, mobile, and Lambda — is TLS 1.3 with modern cipher suites and strict HSTS. No plaintext hops, no protocol downgrades.

AES-256 at rest via AWS KMS

DynamoDB, S3, RDS — every byte encrypted with customer-managed KMS keys. Keys rotate automatically. Backups inherit the same encryption envelope.

Cognito-managed identity

Authentication runs on AWS Cognito with optional MFA. We never store passwords ourselves; Cognito handles hashing, rotation, and brute-force protection.

Daily backups with 30-day retention

Point-in-time recovery for every database. Immutable snapshots in a separate account limit blast radius if anything goes wrong.

Independent audit on the roadmap

Annual third-party penetration test, quarterly dependency audits, automated secret scanning on every commit. We'll publish the security changelog publicly once we have results to share.

Responsible disclosure

Found a vulnerability? Email security@wealthflows.app — we respond within 48 hours and pay a bounty for reproducible issues.