Your security is our top priority. Learn about our comprehensive security measures.
FinVI takes security seriously. As a financial technology platform handling sensitive user data, market information, and payment details, we implement industry-leading security practices to protect your information.
This page outlines our security infrastructure, data protection measures, and compliance standards.
Platform: Vercel (AWS infrastructure)
Platform: Supabase (Managed PostgreSQL)
We support secure OAuth authentication through trusted providers (Google, GitHub) without ever accessing your passwords. OAuth tokens are encrypted and stored securely.
All payment processing is handled by Stripe, a PCI Service Provider Level 1 certified processor. This is the highest level of certification available in the payments industry.
All user inputs are validated, sanitized, and escaped to prevent injection attacks (SQL, XSS, CSRF).
API endpoints are rate-limited (100 requests/minute per user) to prevent abuse and DDoS attacks.
Automated dependency scanning (Dependabot) and regular security updates for all third-party packages.
Real-time error tracking (Sentry) with automatic alerting for security-related issues.
Comprehensive logging of security-relevant events (authentication, data access, admin actions).
EU data protection compliance
California privacy rights
Payment card security (via Stripe)
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:
Please DO NOT: Test against production systems, access other users' data, or perform destructive tests. Use our staging environment if available.
While we implement robust security measures, your account security also depends on your actions:
If you have questions about our security practices or want to report a concern: