DonateLifetime DealInvestServeJoin

Trust

Security

This page is maintained by ALTARED Analytics to describe our current security practices. It is not an independent certification.

Access & authentication

Every account is protected by email + password sign-in with optional single sign-on. Sessions are short-lived and refresh tokens rotate. Role-based permissions govern who can see and change what — access is granted least-privilege by default.

Data isolation

Every table in our database is protected by row-level security policies. Users can only see data their role explicitly permits.

Encryption

All traffic is encrypted in transit with TLS. Data at rest is encrypted by our infrastructure provider.

Backups

The database is backed up continuously with point-in-time recovery available to our team.

Audit logging

Sensitive actions — role changes, admin actions, financial entries — are recorded in an append-only audit log.

Report a vulnerability

If you believe you've found a security issue, please tell us through the responsible disclosure form. We aim to respond within one business day.

Shared responsibility: platform capabilities described above come from our infrastructure providers; day-to-day operational controls are managed by ALTARED Analytics. Customer commitments to their own data governance remain their responsibility.