STOXAVA uses a risk-based security program designed for a financial-planning platform. This page describes the program without claiming a certification or guarantee that does not exist.
1. Our security approach
STOXAVA is designed to handle sensitive financial, tax-planning, employment, and connected-account information. We use administrative, technical, and organizational safeguards intended to reduce the risk of unauthorized access, use, disclosure, alteration, or loss. Security is an ongoing process, and no website, application, or storage system can be guaranteed to be completely secure.
2. Security program principles
- Data minimization. Collect and retain information that is reasonably necessary for the Services, professional engagements, security, and legal obligations.
- Secure transmission. Use encrypted connections designed to protect information transmitted between supported browsers or applications and STOXAVA services.
- Protected storage. Use appropriate encryption, tokenization, segregation, or comparable safeguards for sensitive stored information based on risk and system design.
- Access controls. Limit access to personnel and service providers with a legitimate business need and apply role-based or least-privilege principles where appropriate.
- Authentication. Use account-authentication controls and support additional verification methods where appropriate to the feature and risk.
- Logging and monitoring. Maintain security and operational logs and monitor for suspicious activity, misuse, errors, and reliability issues.
- Secure development. Consider security during design, development, testing, deployment, dependency management, and change review.
- Vendor oversight. Evaluate providers that process sensitive information and require appropriate contractual, privacy, and security commitments.
- Incident response. Maintain procedures to investigate, contain, document, and respond to suspected security incidents and provide notices when required by law.
- Retention and disposal. Delete, deidentify, or securely dispose of information when it is no longer reasonably required, subject to legal and operational retention needs.
- Regulatory safeguards. Where the Gramm-Leach-Bliley Act Safeguards Rule or another financial-security requirement applies, STOXAVA will maintain the additional written program, accountable personnel, risk assessment, service-provider oversight, testing, incident-response, and regulatory-reporting measures required for the covered activities.
3. Connected financial accounts
When STOXAVA uses Plaid or another approved provider, the provider handles the financial-institution authentication experience. STOXAVA does not ask users to enter financial-institution usernames or passwords into a STOXAVA email, support message, or ordinary STOXAVA form. The provider may collect credentials or other authentication information under its own privacy notice when required by the institution.
After a successful connection, STOXAVA receives authorized account data and access tokens or similar technical identifiers needed to retrieve the selected information. Tokens and imported financial data are treated as sensitive. Unless a feature expressly states otherwise, connected-account access is intended for information retrieval and does not permit STOXAVA to move funds or place trades.
4. Professional access
When a user requests a professional service, the selected professional or firm may receive access to information reasonably necessary for that engagement. Access should be limited to the service scope and permissions, and the professional or firm may also have independent security, privacy, and recordkeeping obligations.
5. What users should do
- Use a unique password and do not reuse it on other services.
- Protect access to your email account and devices, because they may be used for account recovery or authentication.
- Use multi-factor authentication when offered.
- Review connected accounts and activity and promptly report anything unexpected.
- Keep browsers, operating systems, and security software updated.
- Do not send passwords, one-time codes, full Social Security numbers, or complete financial-account numbers by email or social media.
- Confirm that communications claiming to be from STOXAVA use an expected channel before opening attachments or entering information.
6. Reporting a security concern
Report suspected unauthorized access, phishing, fraud, data exposure, or a security vulnerability to support@stoxava.com with “Security Report” in the subject line. STOXAVA will route that message to the person responsible for security review. Include a clear description, the affected page or feature, approximate date and time, and steps to reproduce when relevant. Do not include passwords or unnecessary personal or financial information.
Do not publicly disclose a suspected vulnerability or access another person’s information. We may request additional details and will evaluate reports based on severity, reproducibility, potential impact, and legal requirements.
7. Security incidents and notices
If STOXAVA becomes aware of a security incident, we will investigate, contain, remediate, and document the event as appropriate. If we confirm a breach that requires notice, we will notify affected users and applicable authorities without unreasonable delay and within the time required by applicable law, subject to the time reasonably necessary to determine the scope, restore system integrity, and comply with a lawful law-enforcement delay. Where a financial-security rule requires regulatory reporting, STOXAVA will make the report within the applicable threshold and deadline.
8. Third-party services
Some features depend on independent providers, financial institutions, professionals, and partner firms. STOXAVA does not control every part of an independent third party’s systems. Review the provider’s security and privacy information before using the service.
9. No absolute guarantee or unverified claims
Security safeguards reduce risk but cannot eliminate it. STOXAVA does not claim “perfect security,” “military-grade security,” “bank-level security,” SOC 2 certification, or another certification unless the claim is current, documented, and expressly published by STOXAVA.
10. Updates
We may update this page as our platform, providers, safeguards, and legal obligations change. The effective date identifies the current version.
Contact us
Questions about this document: support@stoxava.com. Do not send passwords, full account numbers, Social Security numbers, or other highly sensitive information by email or social media.
