We take the protection of your financial data seriously. This page summarizes the controls described in our Information Security Policy.
Encryption
- All traffic encrypted in transit with TLS 1.2+.
- Credentials and financial access tokens encrypted at rest with AES-256-GCM.
- All data stored in a managed PostgreSQL database with AES-256 encryption at rest.
- Passwords hashed with scrypt.
Access control
- Least-privilege access and strict per-user data isolation — each account can access only its own data.
- Unique, named accounts; centralized identity via single sign-on for infrastructure and source control.
- Multi-factor authentication available to users and required on the systems that host and process data.
- Access is reviewed at least quarterly and revoked immediately on offboarding.
Vulnerability management
- Automated dependency vulnerability scanning on the source repository, with a minimal dependency footprint.
- Defined patch SLA: critical/high within 7 days, medium within 30, low within 90.
- Infrastructure patched automatically by our managed cloud provider; end-of-life software monitored and upgraded before EOL.
Zero-trust principles
No trusted internal network: every request is authenticated and authorized regardless of origin; services communicate only over TLS; hosting is on a managed cloud provider.
Your data
You log in to your bank inside Plaid’s secure window — Profitava never sees your bank credentials. See our Privacy Policy and Data Retention & Deletion Policy for what we collect, how long we keep it, and how to delete it.
Reporting
Found a security issue? Please email support@rejaofficial.com.