Cybersecurity Policy
Last updated: September 3, 2026
1. Purpose and Scope
This Cybersecurity Policy sets requirements for protecting our services, systems, and information from unauthorized access, alteration, disclosure, disruption, or destruction. It applies to Stratifyre personnel, contractors, systems, and applications that process Stratifyre information. Requirements for service providers are addressed through provider assessment and applicable agreements.
The operational requirements below describe expected practices; they are not an attestation that every control has been implemented or independently verified in every environment. Specific application controls are described where relevant. Stratifyre management is responsible for assigning control owners and reviewing this policy at least annually and after material changes or incidents. Exceptions must have a documented risk assessment, management approval, an owner, mitigating safeguards, and a review or expiry date.
This policy supplements our Privacy Policy andTerms of Service. It does not change the purposes for which we collect or share personal information, override applicable law or written agreements, or create an uptime or recovery-time guarantee.
2. Data Classification and Handling
Information must be classified according to its sensitivity and the impact that unauthorized access, use, disclosure, modification, or loss could have:
- Public: Information approved for public release, such as marketing content and published documentation.
- Internal: Non-public business, technical, and operational information that must remain within approved systems and authorized teams.
- Confidential: Customer account information, trading strategies, backtest results, proprietary business information, and non-public logs or reports. Access and sharing must be limited to authorized recipients with a business need, consistent with our Privacy Policy.
- Restricted: Passwords, encryption keys, broker API keys and OAuth tokens, session credentials, payment secrets, authentication factors, and other information that could directly enable unauthorized access. These secrets must be kept in approved credential storage and shared only through authorized, encrypted channels for a specific operational need.
Collection, retention, and disposal must follow our Privacy Policy, including retention needed for legal obligations, billing records, dispute resolution, and enforcement of agreements. Information must be securely deleted or de-identified when those purposes no longer require it. Restricted information must not be placed in source code, tickets, public repositories, or application logs. Copies, exports, and backups must receive protections appropriate to the highest classification they contain. Production data must not be used in development or testing unless authorized and protected.
3. Access Control and Privileged Access Management
Access must be limited to the permissions needed for an approved role or task. Personnel and system owners must ensure that:
- Personnel use individually assigned accounts and do not share credentials.
- Access is approved for a defined business purpose, reviewed periodically, and removed or adjusted when responsibilities change or employment ends.
- Privileged operations are restricted to authorized administrators, separated from ordinary user activity where practicable, and logged for review.
- Administrative access uses strong authentication and multi-factor authentication where supported. Exceptions require documented safeguards and management approval.
- Emergency access is authorized, limited to the incident, recorded, and reviewed afterward. Temporary privileges are removed when no longer needed.
- Secrets are stored and accessed through controlled configuration or secret management mechanisms, with access limited to the services and people that require them.
Stratifyre provides optional authenticator-app two-factor authentication for web accounts. Administrative support impersonation sessions have an absolute time limit and audit records identifying the administrator and target account.
Personnel must protect authentication factors, use approved devices and software, lock unattended devices, and report suspected credential compromise promptly. Stratifyre may suspend sessions, rotate credentials, or restrict access when a security risk is identified.
4. Encryption of Data at Rest and in Transit
Customer-facing connections must use HTTPS with Transport Layer Security (TLS). Connections between services and to providers that carry Confidential or Restricted information must also use encrypted transport with certificate validation. System owners must document and address any gaps in coverage.
The application encrypts stored broker credentials and two-factor authentication secrets using AES-256-GCM authenticated encryption with per-user derived keys. Master encryption keys are supplied separately from the encrypted database records. This application-level protection does not by itself establish encryption of every database, disk, export, or backup.
System owners must provide encryption at rest for Confidential and Restricted information, including backups and exports, and document the scope of that protection. Passwords must be protected using salted, one-way password hashing. Encryption keys must have restricted access, secure recovery arrangements, and procedures for rotation or revocation following suspected compromise. Plaintext secrets must be limited to authorized operations and must not be written to logs or returned through ordinary account-information interfaces.
5. Vulnerability and Patch Management
System owners must identify and track security weaknesses in applications, dependencies, infrastructure, and configuration. They must maintain an inventory of supported components, review relevant security advisories and reports, and select vulnerability checks appropriate to the system. Development checks include automated secret scanning and software validation; these checks do not replace vulnerability assessment of deployed systems.
Each finding must have an owner, a remediation deadline based on severity, exploitability, exposure, and impact, and a record of resolution. Critical or actively exploited issues require prompt assessment for emergency patching, isolation, or other containment. Patches must be tested as appropriate to the risk, deployed through the change process, and checked for effectiveness. Delayed remediation requires documented mitigating safeguards and an approved, time-limited exception.
Unsupported components must be upgraded, replaced, or covered by an approved exception. Security findings must be handled as confidential information and shared only with authorized recipients involved in response or remediation.
6. Security Monitoring and Secure Development
System owners must select security events to log and review, establish escalation paths for suspicious activity, and protect audit records against unauthorized access or alteration. Logs must exclude credentials and limit personal information to what is needed for operation and investigation.
Software and infrastructure changes must receive review and validation appropriate to their security impact before release. Production access and credentials must be separated from development and test access. Personnel must receive security guidance relevant to their responsibilities.
7. Incident Response
Suspected or confirmed security incidents must be escalated to the responsible Stratifyre personnel. Management must assign an incident lead to coordinate:
- Detection, validation, severity assessment, and escalation
- Containment, eradication, and service recovery
- Preservation of relevant evidence and investigation records
- Coordination with affected service providers and other necessary parties
- Post-incident review and corrective actions to reduce recurrence
If an incident affects customer information, we will assess the incident and provide notices to affected customers, authorities, and other required parties within the timeframes and through the channels required by applicable law or contractual commitments. Investigation and recovery must preserve relevant evidence and protect the confidentiality of incident records.
8. Disaster Recovery and Business Continuity
System owners must document backup and recovery procedures for critical systems, including responsible personnel, dependencies, backup frequency and retention, and restoration steps. Plans must address outages, data corruption, infrastructure loss, and security incidents. Recovery copies must be protected from unauthorized access, modification, and deletion, with separation from production failures and access controls appropriate to their classification.
Owners must set recovery priorities, target restoration times, and acceptable data-loss windows for each critical system. Restoration exercises must be scheduled according to risk and after material changes, with results and corrective actions recorded. Restored systems must be checked for data integrity and security before normal operation resumes. These are planning requirements; this policy does not promise a specific recovery time or backup frequency.
9. Physical Security
Physical controls apply to company-managed hardware, personnel workspaces, and third-party hosting facilities. Access to company-managed equipment must be limited to authorized personnel; visitors must be authorized and supervised. System owners must assess protection against theft, power loss, fire, and other environmental hazards. For provider-operated facilities, the responsible owner must assess the provider's physical and environmental safeguards and document the division of responsibilities.
Stratifyre personnel must secure company devices and work areas, prevent unauthorized viewing or removal of information, and report lost, stolen, or compromised equipment promptly. Storage media must be securely erased or destroyed before disposal or reuse.
10. Third-Party Providers
Responsible owners must assess providers that process or support access to Stratifyre information based on the service and information involved. Applicable agreements must address confidentiality, security responsibilities, access limitations, incident notification, and return or disposal of data. Use of a provider does not remove Stratifyre's obligations under applicable law or its agreements with customers.
11. Customer Responsibilities
Customers are responsible for protecting their accounts, devices, and third-party credentials. Customers should use a unique, strong password, enable two-factor authentication, review connected applications and scopes, avoid sharing credentials, keep devices and browsers updated, and promptly revoke or rotate credentials that may have been exposed. Customers should contact Stratifyre promptly if they suspect unauthorized account activity or access to their information.
12. Reporting Security Issues
To report a suspected vulnerability, account compromise, privacy or security incident, or other security concern, email[email protected] with the subject "Security report". Include a description, the affected service, and a way to contact you. Do not send passwords, API keys, private keys, customer data, or sensitive attachments; request a suitable transfer method if evidence is needed. Please do not post security reports in public community channels. Privacy questions may also be sent to[email protected].
13. Changes to This Policy
We may update this Cybersecurity Policy as our services, safeguards, or legal obligations change. We will post the revised policy on this page and update its revision date. Material changes may also be communicated through the Stratifyre service or by email where appropriate.