Security at Epsilo

Your account holds the data behind every investing decision you make through Epsilo. Here's exactly how we protect it.

Encryption in transit

Every connection between your browser, our APIs, and our infrastructure runs over TLS 1.2+ with modern cipher suites. Static assets are served via CloudFront with HTTPS-only redirects.

Encryption at rest

All databases (DynamoDB), object storage (S3), and backups are encrypted at rest using AWS-managed AES-256 keys. Sensitive secrets (broker tokens, OAuth credentials) live in AWS Secrets Manager.

Multi-factor authentication

Every account can enable TOTP-based 2FA (Google Authenticator, 1Password, Authy). Backup codes are issued at enrolment for recovery. Admin actions are gated behind a fresh-auth check.

AWS infrastructure

Epsilo runs on AWS (us-east-1) using Lambda, API Gateway, DynamoDB, S3, Cognito, and CloudFront — every service inherits AWS's underlying physical security, network isolation, and compliance posture.

Audit logging

Every admin action, authentication event, and billing change is logged to CloudWatch with the actor, IP, and timestamp. We can produce an audit trail on request for enterprise customers.

Compliance posture

SOC 2 Type II audit is in progress. We follow OWASP ASVS Level 2 guidelines, run dependency scanning (Dependabot) on every PR, and enforce a Content Security Policy on every authenticated page.

Your data, your control

Account deletion (Settings → Account → Danger Zone) wipes your profile, watchlists, portfolios, signals, and notifications within 30 days — GDPR Article 17 / CCPA "right to be forgotten" compliant. Export your data on request.

Responsible disclosure

Found a vulnerability? Email security@epsilo.app — we'll triage within 48 hours, acknowledge legitimate findings publicly (with your consent), and won't pursue good-faith research.

Questions, audits, or DPAs?

We're happy to walk through our infrastructure with security teams, provide a signed Data Processing Agreement, or share our sub-processor list. Reach the security team directly at security@epsilo.app.

For account-specific issues (lost 2FA device, suspicious activity, account recovery), email support@epsilo.app instead — that goes to a 24h SLA queue.