EST. MMXXV

Trust & Security

Atrium Wealth Council is built by Alter3d Development LLC. This page summarizes how we protect your financial information, the vendors we rely on, and how to reach us about security.

Security posture

  • TLS 1.2+ everywhere; HSTS on all production hostnames.
  • Row-Level Security on every user table — server-enforced, not client-checked.
  • Admin actions verified via server-side role checks (`has_role()`), never client storage.
  • Secrets stored in Lovable Cloud's managed vault, never in the codebase.
  • CSP, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy on all responses.
  • Stripe webhooks validated by signature; JWTs verified on protected functions.
  • Tamper-evident audit log of role, billing, household, and account-deletion events.
  • Automated CI: lint, typecheck, unit tests, RLS tests, end-to-end auth flows, dependency scan.

Data handling

Financial data you enter is stored encrypted at rest in our managed Postgres database and is only accessible to you (and household members you've explicitly invited). Uploaded documents live in private storage buckets, scoped to your user ID.

You can export or delete your account at any time from your profile. Deletion cancels active subscriptions, removes uploaded files, and erases owned rows within minutes.

Subprocessors

We share data only with the vendors required to operate the service:

VendorPurposeRegionPolicy
SupabaseDatabase, authentication, file storageUSLink
StripePayment processing & subscription billingGlobalLink
CloudflareEdge hosting, DDoS protection, TLS terminationGlobalLink
LovableApplication hosting platform & AI GatewayEU/USLink
ResendTransactional email deliveryUSLink
OpenAI / Google (via Lovable AI)Large language model inference for in-app agentsUSLink

Compliance status

We are not currently SOC 2 certified. We follow controls aligned with the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality) and operate on infrastructure (Supabase, Stripe, Cloudflare) that maintains its own SOC 2 Type II reports. A formal audit is on our roadmap.

Incident response

If we discover a breach affecting your data, we will notify affected members by email without undue delay, and in any case within 72 hours of confirmation, with the facts known at the time and the steps we are taking.

Responsible disclosure

Found a vulnerability? Please email contact@atriumwealthcouncil.com with reproduction steps. Full policy at /.well-known/security.txt.