Security

Security at DueVestor

How we keep your data — and your subjects' data — safe in transit, at rest, and against insider threat.

Encryption

TLS 1.2+ in transit (Cloudflare-terminated, modern ciphers). Database backups are encrypted before they leave the host.

Access controls

Production access is limited to a single founder operator. Sensitive admin operations go through an audit log (ADR-058) with 2-year retention. API access is opaque per-key (HMAC-SHA256 hashed; ADR-056) — a leaked DB dump cannot replay a key without the application secret.

Edge firewall & DDoS protection

DueVestor runs behind Cloudflare's Pro-tier network — providing Web Application Firewall (WAF) capability, automatic DDoS mitigation, and bot filtering at the network edge. Managed WAF rules protect against OWASP Top 10 attack patterns before they reach the application layer.

Reporting a vulnerability

Email [email protected] with a description, reproduction steps, and your suggested CVSS. We commit to a 72-hour acknowledgement and a 30-day fix-or-explain. No money rewards in v1; public credit on the post-mortem if you want it.

What we send to LLMs

Subject data sent to Anthropic flows under a no-training contract — it is not used to train models.

Sub-processors

DueVestor uses the following sub-processors to deliver the service. We notify customers 30 days before adding any sub-processor that processes EU personal data.

VendorPurposeRegion
RunPodHosting — application, database, workersEEA
CloudflareCDN + DNS + WAF + DDoS protection + file storage (R2)Global
AnthropicLLM inference (no-training contract)US
ResendTransactional emailUS
TwilioSMS / phone verificationUS
PayPalCredit purchasesUS
GitHubSource code hosting (no user data)US

Need a signed DPA?

Customers can request a signed Data Processing Agreement.

View / sign DPA →