Encryption in transit
Every connection between your browser, our APIs, and our infrastructure runs over TLS 1.2+ with modern cipher suites. Static assets are served via CloudFront with HTTPS-only redirects.
Your account holds the data behind every investing decision you make through Epsilo. Here's exactly how we protect it.
Every connection between your browser, our APIs, and our infrastructure runs over TLS 1.2+ with modern cipher suites. Static assets are served via CloudFront with HTTPS-only redirects.
All databases (DynamoDB), object storage (S3), and backups are encrypted at rest using AWS-managed AES-256 keys. Sensitive secrets (broker tokens, OAuth credentials) live in AWS Secrets Manager.
Every account can enable TOTP-based 2FA (Google Authenticator, 1Password, Authy). Backup codes are issued at enrolment for recovery. Admin actions are gated behind a fresh-auth check.
Epsilo runs on AWS (us-east-1) using Lambda, API Gateway, DynamoDB, S3, Cognito, and CloudFront — every service inherits AWS's underlying physical security, network isolation, and compliance posture.
Every admin action, authentication event, and billing change is logged to CloudWatch with the actor, IP, and timestamp. We can produce an audit trail on request for enterprise customers.
SOC 2 Type II audit is in progress. We follow OWASP ASVS Level 2 guidelines, run dependency scanning (Dependabot) on every PR, and enforce a Content Security Policy on every authenticated page.
Account deletion (Settings → Account → Danger Zone) wipes your profile, watchlists, portfolios, signals, and notifications within 30 days — GDPR Article 17 / CCPA "right to be forgotten" compliant. Export your data on request.
Found a vulnerability? Email security@epsilo.app — we'll triage within 48 hours, acknowledge legitimate findings publicly (with your consent), and won't pursue good-faith research.
We're happy to walk through our infrastructure with security teams, provide a signed Data Processing Agreement, or share our sub-processor list. Reach the security team directly at security@epsilo.app.
For account-specific issues (lost 2FA device, suspicious activity, account recovery), email support@epsilo.app instead — that goes to a 24h SLA queue.