2026 early-access offer: Double credits through end of 2026.

Legal & compliance

Security Policy

Last updated 2026-06

Last updated: June 2026

These policies are published in English. In the event of any discrepancy between the English version and any translated version on this website, the English version prevails.

01 Scope & purpose

What this policy covers

We maintain a documented security policy to identify, limit, and monitor risks to the confidentiality, integrity, and availability of our systems, your data, and our partner integrations.

This policy applies to:

  • All A2B2 production systems and services
  • All staff, contractors, and third-party processors with access to our systems or data
  • All data processed on your behalf, including financial data retrieved via third-party financial connectivity integrations
  • Third-party integrations and sub-processors

02 Infrastructure

How we're built

Cloud provider: AWS us-east-1 (sole production cloud provider).

Architecture: Web / mobile clients → Edge WAF / CDN → API Gateway (Nginx) → BFF services (FastAPI, modular: auth / research / scour / connect / own / plaid / admin) → Data layer (PostgreSQL + Redis + pgvector).

Environment separation: Development / Sandbox (CI/dev), QA / Demo, and Production are maintained as separate environments with separate credentials and access controls. No production data in lower environments.

Secrets management: AWS KMS + AWS Secrets Manager with DEK/KEK structure and controlled key rotation.

03 Encryption

How we protect your data

LayerStandard
Data in transitTLS 1.2+ - all client↔server and server↔third-party service communications
Data at restAES-256-GCM - all persistent storage including Plaid access tokens
Third-party access tokensEncrypted with AES-256-GCM before storage; decrypted in-memory per API call only; never transmitted to client or logged
Financial documentsPrivate storage with bucket-level encryption keys and temporary access links; not accessible via public URLs
Key managementAWS KMS with DEK/KEK structure; rotation schedule and break-glass procedure documented

04 Access control

Who can see what

  • Internal authentication: Google Workspace SSO with MFA enforced for all staff
  • API authentication: JWT-based; middleware stack enforces host allowlisting, HTTPS redirect, strict CORS, request ID tagging, and Redis sliding-window rate limiting
  • Least privilege: Applied across all system roles; production access limited to minimum necessary personnel
  • Third-party token access: Restricted to the relevant BFF service layer only; token decryption path is isolated from all other services
  • Audit logging: All administrative actions are recorded in an immutable audit log and reviewed quarterly
  • Access reviews: Quarterly review of all production access rights

Your data stays yours. Queries, uploaded documents, and portfolio positions you share with A2B2 are never visible to other users, advertisers, brokers, financial institutions, or A2B2 staff without your explicit consent.

05 Network security

How we secure the perimeter

  • Edge WAF: In place at all ingress points; filters malicious traffic before it reaches application services
  • Rate limiting: Redis-based sliding window at API gateway; per-IP and per-account throttling
  • CORS: Strict origin allowlisting enforced at all API endpoints
  • VPC segmentation: Production services isolated within VPC with defined security groups; database layer not publicly accessible
  • DDoS protection: AWS Shield via CloudFront at edge

06 Application security

How we secure the code

ActivityTool / standard
SAST (static analysis)Snyk - integrated in CI/CD pipeline; runs on every commit and pull request
Dependency / SCA scanningSnyk - automated alerts on new CVEs in dependencies
Penetration testingExternal penetration test planned for Q3 2026, post-launch; annual cadence thereafter or after any material infrastructure change. Vendor to be confirmed. Internal testing completed.
Webhook security (Plaid)Plaid webhook signature verification via Plaid-Verification JWT header; unverified payloads rejected
Code reviewAll production changes require peer review before merge

Vulnerability remediation SLAs: Critical - 24 hours; High - 7 days; Medium - 30 days.

No background data mining: A2B2 never uses your data to train AI models without explicit opt-in consent, and never mines interaction data for advertising.

07 Logging & monitoring

How we watch for problems

  • Observability platform: Datadog (logging, metrics, alerting)
  • Log retention: 90 days (all service and access logs); automated purge after 90 days
  • Request tracing: Correlation IDs on all requests; structured logging throughout
  • PII / token redaction: Plaid tokens and financial credentials are excluded from all log output
  • Audit trail: Immutable audit log of all administrative and privileged access actions
  • Alerting: Automated alerts on anomalous access patterns, error rate spikes, and security events

08 Vendor security

How we vet third parties

Critical vendors are assessed at onboarding and annually. All sub-processors must meet equivalent encryption and access control standards, and provide prompt breach notification.

VendorRoleAssessment
Plaid Inc.Investment data connectivity (OWN)DPA in place; Plaid security review process; OAuth-only access (no credential storage)
AWSCloud hosting (us-east-1)SOC 2 Type II; ISO 27001; AWS DPA
DatadogObservability and loggingDPA in place; PII redaction confirmed; security assessment completed
Western LLM providers (OpenAI, Anthropic/Claude, Google/Gemini)AI model inferenceDPAs in place; training prohibition confirmed; ZDR where provider amendments confirm it - see vendor register
Chinese LLM providers (DeepSeek, Qwen, Kimi)Non-personal AI tasks only (pending legal clearance)Not cleared for processing personal or financial data. Subject to additional cross-border transfer and legal assessment before production use.

09 Incident response

What happens when something goes wrong

We maintain a documented incident response runbook covering detection, containment, third-party access token revocation, user notification, and partner notification.

Account security event notifications

We'll notify you promptly if we detect: a login from an unrecognised device or location; a password change you didn't initiate; MFA setting changes you didn't make; or unusual session activity that triggers security flags.

Account takeover response

If we detect a suspected compromise, we will terminate active sessions immediately, lock the account temporarily, and guide you through identity verification to restore access. Your OWN data connection will be suspended pending investigation. Contact security@a2b2.ai immediately if you believe your account has been accessed without your permission.

MFA guidance: MFA (via authenticator app or SMS) is strongly recommended for all accounts and required for all A2B2 staff. For accounts with active OWN portfolio connections, enabling MFA is strongly advised to protect financial data access. MFA setup is available at Account Settings → Security.

Breach notification

If we become aware of a security breach affecting your personal data:

  • Regulators: Notified within 72 hours - HK Privacy Commissioner (PCPD); applicable US state breach notification authorities
  • Affected users: Notified without undue delay where there is high risk to your rights and interests, including what happened, what data was affected, steps taken, and how to contact us or freeze your account

Your security responsibilities

Use a strong, unique password; enable two-factor authentication; never share credentials; log out on shared or public devices; report suspicious activity immediately to security@a2b2.ai.

10 Responsible disclosure

Found a vulnerability?

If you find a vulnerability, email security@a2b2.ai with a description, reproduction steps, and potential impact.

Email security@a2b2.ai. You'll receive an acknowledgement, and the team will keep you updated through the investigation. A2B2 operates under responsible disclosure principles - genuine security research is welcomed.

Please: Do not access or modify user data while investigating. Do not conduct denial-of-service testing. Allow us reasonable time to remediate before public disclosure. We do not operate a paid bug bounty programme at this time.

11 Regulatory compliance

The frameworks we operate under

We operate under the Publisher's Exclusion of the US Investment Advisers Act of 1940 and Hong Kong's Broadcaster/Journalist exemption under SFO Schedule 5. The platform provides intelligence, not regulated financial advice.

We honour data privacy rights under GDPR (where applicable), CCPA/CPRA (California), PDPO (Hong Kong), and other applicable US state privacy laws. To exercise your rights, contact privacy@a2b2.ai.

SOC 2 Type II audit: Currently underway, covering privacy, security, availability, and confidentiality. Final reports are available to enterprise clients under NDA on completion.

12 Roles & responsibilities

Who owns what

RoleResponsibility
COOPolicy owner; annual review sign-off; risk treatment decisions
CTO / Engineering LeadTechnical implementation; control design; security architecture; incident response lead
Engineering teamOperational adherence; vulnerability remediation; audit log architecture
All staffMandatory MFA; compliance with access control procedures; incident reporting

We review this policy annually and whenever there is a material change to the platform, infrastructure, regulatory environment, or partner requirements.