Security & Data Protection

Your data deserves the highest protection.

finvantage handles sensitive financial data, personal information and confidential documents. Security is not a feature — it is the foundation of everything we build.

Hosting in Germany

Your portfolio data and documents are stored in German data centers (AWS Frankfurt). No third-party CDNs, no external resource loading.

Encryption in transit and at rest

TLS 1.2 or higher on the connection from your browser, with TLS 1.3 preferred. AES-256-GCM for sensitive data at rest. Session tokens are stored only as SHA-256 hashes — even a database leak compromises no sessions.

Strong authentication

Passwords hashed with Argon2id and checked against known breach corpora. Temporary lockout after repeated failed attempts. Session tokens are never stored in recoverable form.

Privacy by design

Data minimization from the ground up. No PII in logs. No tracking. No advertising networks. UUIDs as external identifiers — never internal database IDs.

Audit trail

Registration, sign-in, sign-out and password resets are recorded in a log that is only ever appended to: who did what, when, and from where. Entries carry IP address, user agent and request ID where available. Portfolio and banking data are not covered yet.

Mandant isolation

Strict data separation between organizations at the application level. Mandant boundaries are enforced in the data-access layer, with a fail-closed access predicate and automated isolation tests.

Compliance

Built to meet the highest standards.

GDPR

Built for the EU General Data Protection Regulation. Your portfolio data and documents are stored in AWS Frankfurt (eu-central-1). Where we use a processor, it is contracted under Art. 28 GDPR. Requests for access or erasure are handled by our team.

Secure development

Parameterized queries, input validation, CSRF protection, and a Content Security Policy with secure headers on application responses.

Security management

Our security guidelines are documented and versioned alongside the code. We hold no external certification.

Dependency security

Pinned dependency versions with checksums, and a deliberately small dependency footprint.

Questions about security?

We are happy to discuss our security architecture in detail. Reach out to our team for a personal conversation.