Security
Security at DueVestor
How we keep your data — and your subjects' data — safe in transit, at rest, and against insider threat.
Encryption
TLS 1.2+ in transit (Cloudflare-terminated, modern ciphers). Database backups are encrypted before they leave the host.
Access controls
Production access is limited to a single founder operator. Sensitive admin operations go through an audit log (ADR-058) with 2-year retention. API access is opaque per-key (HMAC-SHA256 hashed; ADR-056) — a leaked DB dump cannot replay a key without the application secret.
Edge firewall & DDoS protection
DueVestor runs behind Cloudflare's Pro-tier network — providing Web Application Firewall (WAF) capability, automatic DDoS mitigation, and bot filtering at the network edge. Managed WAF rules protect against OWASP Top 10 attack patterns before they reach the application layer.
Reporting a vulnerability
Email [email protected] with a description, reproduction steps, and your suggested CVSS. We commit to a 72-hour acknowledgement and a 30-day fix-or-explain. No money rewards in v1; public credit on the post-mortem if you want it.
What we send to LLMs
Subject data sent to Anthropic flows under a no-training contract — it is not used to train models.
Sub-processors
DueVestor uses the following sub-processors to deliver the service. We notify customers 30 days before adding any sub-processor that processes EU personal data.
| Vendor | Purpose | Region |
|---|---|---|
| RunPod | Hosting — application, database, workers | EEA |
| Cloudflare | CDN + DNS + WAF + DDoS protection + file storage (R2) | Global |
| Anthropic | LLM inference (no-training contract) | US |
| Resend | Transactional email | US |
| Twilio | SMS / phone verification | US |
| PayPal | Credit purchases | US |
| GitHub | Source code hosting (no user data) | US |
Need a signed DPA?
Customers can request a signed Data Processing Agreement.
View / sign DPA →