Encryption in transit
Every connection between your browser, our APIs, and our infrastructure runs over TLS 1.2+ with modern cipher suites. Static assets are served over a global CDN with HTTPS-only redirects.
Your account holds the data behind every investing decision you make through Epsilo. Here's exactly how we protect it.
Every connection between your browser, our APIs, and our infrastructure runs over TLS 1.2+ with modern cipher suites. Static assets are served over a global CDN with HTTPS-only redirects.
All databases, object storage, and backups are encrypted at rest with AES-256. Sensitive secrets — broker tokens and OAuth credentials — are held in a dedicated, access-controlled secrets store, isolated from application data.
Every account can enable TOTP-based 2FA (Google Authenticator, 1Password, Authy). Backup codes are issued at enrolment for recovery. Admin actions are gated behind a fresh-auth check.
Epsilo runs on Amazon Web Services, inheriting AWS's physical security, network isolation, and compliance posture. Our workloads run in isolated, least-privilege environments with no directly exposed servers.
Every admin action, authentication event, and billing change is written to a centralized, append-only audit log with the actor, IP, and timestamp. We can produce an audit trail on request for enterprise customers.
SOC 2 Type II audit is in progress. We follow OWASP ASVS Level 2 guidelines, run automated dependency scanning on every change, and enforce a Content Security Policy on every authenticated page.
Account deletion (Settings → Account → Danger Zone) wipes your profile, watchlists, portfolios, signals, and notifications within 30 days — GDPR Article 17 / CCPA "right to be forgotten" compliant. Export your data on request.
Found a vulnerability? Email security@epsilo.app — we'll triage within 48 hours, acknowledge legitimate findings publicly (with your consent), and won't pursue good-faith research.
We're happy to walk through our infrastructure with security teams, provide a signed Data Processing Agreement, or share our sub-processor list. Reach the security team directly at security@epsilo.app.
For account-specific issues (lost 2FA device, suspicious activity, account recovery), email support@epsilo.app instead — that goes to a 24h SLA queue.