Security & Trust
Your financial data deserves bank-level protection. Here's how we secure every layer of the Grade My Investments platform.
Multi-Layered Security Architecture
Network Security
Azure VNet, private endpoints, WAF protection
Application Security
OAuth 2.0, RBAC, input validation
Data Security
Azure-managed AES-256 at rest, TLS 1.2+ in transit
Monitoring
Real-time alerts, audit logs, anomaly detection
Encryption
Data in Transit
- TLS 1.3 on all communications
- Perfect Forward Secrecy (PFS)
- HTTP Strict Transport Security (HSTS)
- Strong cipher suites only
Data at Rest
- Azure-managed AES-256 server-side encryption (SSE) on all stored data
- Azure MySQL Flexible Server encryption at rest (Azure-managed SSE)
- Microsoft-managed encryption keys
- Azure Blob Storage server-side encryption for all report files
Authentication
Google Sign-In (Investors)
- OAuth 2.0 / OpenID Connect
- Google handles all credential management
- We never see or store your password
- Multi-factor authentication via Google
- Automatic token refresh
- 60-minute idle session timeout
Mobile App Security
- PKCE (Proof Key for Code Exchange) on all platforms
- No client secrets stored in app binaries
- Platform SecureStorage for tokens
- Biometric authentication support
- Certificate pinning for API calls
Cloud Infrastructure
- Microsoft Azure — Enterprise-grade cloud hosting with 99.9% SLA
- Private Endpoints — Database is not accessible from the public internet
- Network Security Groups — Firewall rules restrict all traffic to authorized sources
- Azure Key Vault — All secrets, API keys, and connection strings stored in a hardware security module
- Azure Front Door — DDoS protection and Web Application Firewall (WAF)
- Infrastructure as Code — All resources provisioned via auditable templates, no manual configuration
OWASP Top 10 Compliance
Grade My Investments is built to address all 10 OWASP web application security risks:
- A01: Broken Access Control — RBAC + account-scoped data
- A02: Cryptographic Failures — TLS 1.2+ + Azure-managed AES-256
- A03: Injection — Parameterized queries + CSP headers
- A04: Insecure Design — Defense in depth + least privilege
- A05: Security Misconfiguration — Infrastructure as Code
- A06: Vulnerable Components — Automated dependency scanning
- A07: Auth Failures — Delegated auth (Google/Azure AD)
- A08: Integrity Failures — CI/CD pipeline + source control
- A09: Logging Failures — Azure Monitor + Application Insights
- A10: SSRF — No user-controlled URLs + VNet isolation
Your Data
What We Store
- Your Google account email (for sign-in)
- Symbol lists you create
- Generated report files
- Billing and usage records
What We Never Store
- Your passwords (Google handles authentication)
- Full credit card numbers (Stripe handles payments)
- Brokerage account credentials
- Personal financial holdings (unless you upload them)
Payment Security
All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor used by millions of businesses worldwide. Your credit card details are sent directly to Stripe's servers — they never touch our systems.
Questions About Security?
We're happy to answer any questions about how we protect your data.
Contact Us (Free) Privacy Policy