Legal & compliance
Security Policy
Last updated 2026-06
Last updated: June 2026
These policies are published in English. In the event of any discrepancy between the English version and any translated version on this website, the English version prevails.
01 Scope & purpose
What this policy covers
We maintain a documented security policy to identify, limit, and monitor risks to the confidentiality, integrity, and availability of our systems, your data, and our partner integrations.
This policy applies to:
- All A2B2 production systems and services
- All staff, contractors, and third-party processors with access to our systems or data
- All data processed on your behalf, including financial data retrieved via third-party financial connectivity integrations
- Third-party integrations and sub-processors
02 Infrastructure
How we're built
Cloud provider: AWS us-east-1 (sole production cloud provider).
Architecture: Web / mobile clients → Edge WAF / CDN → API Gateway (Nginx) → BFF services (FastAPI, modular: auth / research / scour / connect / own / plaid / admin) → Data layer (PostgreSQL + Redis + pgvector).
Environment separation: Development / Sandbox (CI/dev), QA / Demo, and Production are maintained as separate environments with separate credentials and access controls. No production data in lower environments.
Secrets management: AWS KMS + AWS Secrets Manager with DEK/KEK structure and controlled key rotation.
03 Encryption
How we protect your data
| Layer | Standard |
|---|---|
| Data in transit | TLS 1.2+ - all client↔server and server↔third-party service communications |
| Data at rest | AES-256-GCM - all persistent storage including Plaid access tokens |
| Third-party access tokens | Encrypted with AES-256-GCM before storage; decrypted in-memory per API call only; never transmitted to client or logged |
| Financial documents | Private storage with bucket-level encryption keys and temporary access links; not accessible via public URLs |
| Key management | AWS KMS with DEK/KEK structure; rotation schedule and break-glass procedure documented |
04 Access control
Who can see what
- Internal authentication: Google Workspace SSO with MFA enforced for all staff
- API authentication: JWT-based; middleware stack enforces host allowlisting, HTTPS redirect, strict CORS, request ID tagging, and Redis sliding-window rate limiting
- Least privilege: Applied across all system roles; production access limited to minimum necessary personnel
- Third-party token access: Restricted to the relevant BFF service layer only; token decryption path is isolated from all other services
- Audit logging: All administrative actions are recorded in an immutable audit log and reviewed quarterly
- Access reviews: Quarterly review of all production access rights
Your data stays yours. Queries, uploaded documents, and portfolio positions you share with A2B2 are never visible to other users, advertisers, brokers, financial institutions, or A2B2 staff without your explicit consent.
05 Network security
How we secure the perimeter
- Edge WAF: In place at all ingress points; filters malicious traffic before it reaches application services
- Rate limiting: Redis-based sliding window at API gateway; per-IP and per-account throttling
- CORS: Strict origin allowlisting enforced at all API endpoints
- VPC segmentation: Production services isolated within VPC with defined security groups; database layer not publicly accessible
- DDoS protection: AWS Shield via CloudFront at edge
06 Application security
How we secure the code
| Activity | Tool / standard |
|---|---|
| SAST (static analysis) | Snyk - integrated in CI/CD pipeline; runs on every commit and pull request |
| Dependency / SCA scanning | Snyk - automated alerts on new CVEs in dependencies |
| Penetration testing | External penetration test planned for Q3 2026, post-launch; annual cadence thereafter or after any material infrastructure change. Vendor to be confirmed. Internal testing completed. |
| Webhook security (Plaid) | Plaid webhook signature verification via Plaid-Verification JWT header; unverified payloads rejected |
| Code review | All production changes require peer review before merge |
Vulnerability remediation SLAs: Critical - 24 hours; High - 7 days; Medium - 30 days.
No background data mining: A2B2 never uses your data to train AI models without explicit opt-in consent, and never mines interaction data for advertising.
07 Logging & monitoring
How we watch for problems
- Observability platform: Datadog (logging, metrics, alerting)
- Log retention: 90 days (all service and access logs); automated purge after 90 days
- Request tracing: Correlation IDs on all requests; structured logging throughout
- PII / token redaction: Plaid tokens and financial credentials are excluded from all log output
- Audit trail: Immutable audit log of all administrative and privileged access actions
- Alerting: Automated alerts on anomalous access patterns, error rate spikes, and security events
08 Vendor security
How we vet third parties
Critical vendors are assessed at onboarding and annually. All sub-processors must meet equivalent encryption and access control standards, and provide prompt breach notification.
| Vendor | Role | Assessment |
|---|---|---|
| Plaid Inc. | Investment data connectivity (OWN) | DPA in place; Plaid security review process; OAuth-only access (no credential storage) |
| AWS | Cloud hosting (us-east-1) | SOC 2 Type II; ISO 27001; AWS DPA |
| Datadog | Observability and logging | DPA in place; PII redaction confirmed; security assessment completed |
| Western LLM providers (OpenAI, Anthropic/Claude, Google/Gemini) | AI model inference | DPAs in place; training prohibition confirmed; ZDR where provider amendments confirm it - see vendor register |
| Chinese LLM providers (DeepSeek, Qwen, Kimi) | Non-personal AI tasks only (pending legal clearance) | Not cleared for processing personal or financial data. Subject to additional cross-border transfer and legal assessment before production use. |
09 Incident response
What happens when something goes wrong
We maintain a documented incident response runbook covering detection, containment, third-party access token revocation, user notification, and partner notification.
Account security event notifications
We'll notify you promptly if we detect: a login from an unrecognised device or location; a password change you didn't initiate; MFA setting changes you didn't make; or unusual session activity that triggers security flags.
Account takeover response
If we detect a suspected compromise, we will terminate active sessions immediately, lock the account temporarily, and guide you through identity verification to restore access. Your OWN data connection will be suspended pending investigation. Contact security@a2b2.ai immediately if you believe your account has been accessed without your permission.
MFA guidance: MFA (via authenticator app or SMS) is strongly recommended for all accounts and required for all A2B2 staff. For accounts with active OWN portfolio connections, enabling MFA is strongly advised to protect financial data access. MFA setup is available at Account Settings → Security.
Breach notification
If we become aware of a security breach affecting your personal data:
- Regulators: Notified within 72 hours - HK Privacy Commissioner (PCPD); applicable US state breach notification authorities
- Affected users: Notified without undue delay where there is high risk to your rights and interests, including what happened, what data was affected, steps taken, and how to contact us or freeze your account
Your security responsibilities
Use a strong, unique password; enable two-factor authentication; never share credentials; log out on shared or public devices; report suspicious activity immediately to security@a2b2.ai.
10 Responsible disclosure
Found a vulnerability?
If you find a vulnerability, email security@a2b2.ai with a description, reproduction steps, and potential impact.
Email security@a2b2.ai. You'll receive an acknowledgement, and the team will keep you updated through the investigation. A2B2 operates under responsible disclosure principles - genuine security research is welcomed.
Please: Do not access or modify user data while investigating. Do not conduct denial-of-service testing. Allow us reasonable time to remediate before public disclosure. We do not operate a paid bug bounty programme at this time.
11 Regulatory compliance
The frameworks we operate under
We operate under the Publisher's Exclusion of the US Investment Advisers Act of 1940 and Hong Kong's Broadcaster/Journalist exemption under SFO Schedule 5. The platform provides intelligence, not regulated financial advice.
We honour data privacy rights under GDPR (where applicable), CCPA/CPRA (California), PDPO (Hong Kong), and other applicable US state privacy laws. To exercise your rights, contact privacy@a2b2.ai.
SOC 2 Type II audit: Currently underway, covering privacy, security, availability, and confidentiality. Final reports are available to enterprise clients under NDA on completion.
12 Roles & responsibilities
Who owns what
| Role | Responsibility |
|---|---|
| COO | Policy owner; annual review sign-off; risk treatment decisions |
| CTO / Engineering Lead | Technical implementation; control design; security architecture; incident response lead |
| Engineering team | Operational adherence; vulnerability remediation; audit log architecture |
| All staff | Mandatory MFA; compliance with access control procedures; incident reporting |
We review this policy annually and whenever there is a material change to the platform, infrastructure, regulatory environment, or partner requirements.