1. Purpose and scope
This Information Security Policy describes how Endval identifies, mitigates, and monitors information security risks relevant to operating our portfolio tracking service (the “Service”). It applies to the Service, production systems, customer data, and third-party integrations used to deliver the Service.
2. Security roles and responsibilities
Endval designates an information security contact responsible for security inquiries, vendor security reviews, and incident coordination. Security-related questions and reports may be sent to endval.support@gmail.com.
3. Data classification
We categorize data handled by the Service as follows:
- Account data, name, email, authentication credentials, subscription status, and preferences.
- Portfolio data, holdings, cost basis, trades, and related analytics entered by users or imported via CSV or broker linking.
- Sensitive credentials, OAuth and API tokens for optional broker linking (e.g., Plaid), stored encrypted at rest.
- Operational data, logs, usage metrics, and system configuration required to operate the Service.
4. Technical controls
We implement technical safeguards appropriate to the sensitivity of the data we process, including:
- HTTPS for data in transit to and from the Service.
- Hashed storage of user passwords using industry-standard algorithms.
- Encrypted storage of third-party broker access tokens using symmetric encryption with keys held separately from application data.
- Session-based authentication with time-limited sessions and server-side validation for protected API routes.
- Role- and subscription-based access controls for premium features, including optional broker linking.
- Scheduled background jobs for broker sync protected by authenticated cron endpoints.
5. Administrative and organizational controls
We limit production access to personnel who require it to operate and support the Service. Changes to production systems follow review through our standard development and deployment workflow. We use established cloud providers for hosting and data storage and assess vendors that process customer or sensitive data before integration.
6. Third-party services and broker linking
The Service integrates with third parties for payments, market data, AI inference, email, and optional broker account linking. Broker linking through Plaid is optional, read-only for portfolio import purposes, and subject to the user's authorization through the provider's consent flow. We do not sell customer portfolio data. Third-party providers are expected to maintain appropriate security controls under their own terms and policies.
7. Risk identification and monitoring
We identify and address security risks through development practices, dependency updates, access reviews, monitoring of production errors, review of vendor security requirements, and response to reported vulnerabilities or incidents. Security considerations are included when designing features that handle authentication, financial data, or third-party credentials.
8. Incident response
If we become aware of a security incident affecting customer data, we will investigate, contain, and remediate the issue, and notify affected users or regulators when required by applicable law. Security incidents may be reported to endval.support@gmail.com.
9. Data retention and disposal
We retain account and portfolio data while an account is active and as needed for legal or operational purposes. Users may request account deletion subject to our Privacy Policy. When data is deleted, we remove or de-identify it from active systems within a reasonable period, subject to backup retention limits.
10. Employee and contractor access
Access to production systems and customer data is granted on a least-privilege basis and only to individuals who need such access to perform their duties. Access is revoked when no longer required.
11. Policy review
We review and update this policy periodically and when material changes occur to our systems, vendors, or regulatory environment. The current version is published at /security.
12. Contact
Security inquiries: endval.support@gmail.com. Privacy inquiries: endval.support@gmail.com.