Security & Trust

Your financial data deserves bank-level protection. Here's how we secure every layer of the Grade My Investments platform.

Multi-Layered Security Architecture

Network Security

Azure VNet, private endpoints, WAF protection

Application Security

OAuth 2.0, RBAC, input validation

Data Security

Azure-managed AES-256 at rest, TLS 1.2+ in transit

Monitoring

Real-time alerts, audit logs, anomaly detection

Encryption

Data in Transit
  • TLS 1.3 on all communications
  • Perfect Forward Secrecy (PFS)
  • HTTP Strict Transport Security (HSTS)
  • Strong cipher suites only
Data at Rest
  • Azure-managed AES-256 server-side encryption (SSE) on all stored data
  • Azure MySQL Flexible Server encryption at rest (Azure-managed SSE)
  • Microsoft-managed encryption keys
  • Azure Blob Storage server-side encryption for all report files

Authentication

Google Sign-In (Investors)
  • OAuth 2.0 / OpenID Connect
  • Google handles all credential management
  • We never see or store your password
  • Multi-factor authentication via Google
  • Automatic token refresh
  • 60-minute idle session timeout
Mobile App Security
  • PKCE (Proof Key for Code Exchange) on all platforms
  • No client secrets stored in app binaries
  • Platform SecureStorage for tokens
  • Biometric authentication support
  • Certificate pinning for API calls

Cloud Infrastructure

  • Microsoft Azure — Enterprise-grade cloud hosting with 99.9% SLA
  • Private Endpoints — Database is not accessible from the public internet
  • Network Security Groups — Firewall rules restrict all traffic to authorized sources
  • Azure Key Vault — All secrets, API keys, and connection strings stored in a hardware security module
  • Azure Front Door — DDoS protection and Web Application Firewall (WAF)
  • Infrastructure as Code — All resources provisioned via auditable templates, no manual configuration

OWASP Top 10 Compliance

Grade My Investments is built to address all 10 OWASP web application security risks:

  • A01: Broken Access Control — RBAC + account-scoped data
  • A02: Cryptographic Failures — TLS 1.2+ + Azure-managed AES-256
  • A03: Injection — Parameterized queries + CSP headers
  • A04: Insecure Design — Defense in depth + least privilege
  • A05: Security Misconfiguration — Infrastructure as Code
  • A06: Vulnerable Components — Automated dependency scanning
  • A07: Auth Failures — Delegated auth (Google/Azure AD)
  • A08: Integrity Failures — CI/CD pipeline + source control
  • A09: Logging Failures — Azure Monitor + Application Insights
  • A10: SSRF — No user-controlled URLs + VNet isolation

Your Data

What We Store
  • Your Google account email (for sign-in)
  • Symbol lists you create
  • Generated report files
  • Billing and usage records
What We Never Store
  • Your passwords (Google handles authentication)
  • Full credit card numbers (Stripe handles payments)
  • Brokerage account credentials
  • Personal financial holdings (unless you upload them)

Payment Security

All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor used by millions of businesses worldwide. Your credit card details are sent directly to Stripe's servers — they never touch our systems.

Questions About Security?

We're happy to answer any questions about how we protect your data.

Contact Us (Free) Privacy Policy