Read-only brokerage access
We connect via SnapTrade and broker OAuth. WealthFlows can see positions and transactions; we can never place trades, move money, or reset passwords. Your credentials never touch our servers.
Read-only access. Encrypted everywhere. Questions? Email security@wealthflows.app.
We connect via SnapTrade and broker OAuth. WealthFlows can see positions and transactions; we can never place trades, move money, or reset passwords. Your credentials never touch our servers.
Every request — browser, mobile, and Lambda — is TLS 1.3 with modern cipher suites and strict HSTS. No plaintext hops, no protocol downgrades.
DynamoDB, S3, RDS — every byte encrypted with customer-managed KMS keys. Keys rotate automatically. Backups inherit the same encryption envelope.
Authentication runs on AWS Cognito with optional MFA. We never store passwords ourselves; Cognito handles hashing, rotation, and brute-force protection.
Point-in-time recovery for every database. Immutable snapshots in a separate account limit blast radius if anything goes wrong.
Annual third-party penetration test, quarterly dependency audits, automated secret scanning on every commit. We'll publish the security changelog publicly once we have results to share.
Found a vulnerability? Email security@wealthflows.app — we respond within 48 hours and pay a bounty for reproducible issues.