Last updated: August 2, 2026
Protecting client information is a core obligation, not a feature. This page describes the controls actually implemented today. We deliberately do not claim certifications we have not obtained.
Client-portal access uses federated sign-in through Google OAuth, so we never see or store your password. Time-based one-time-password (TOTP) two-factor authentication is available and can be required for sensitive areas. Portal sessions are carried in cryptographically signed cookies, are scoped to your account, and expire; signing out invalidates the session.
All traffic between your browser and our systems is encrypted in transit using TLS. Client records and uploaded documents are encrypted at rest using authenticated symmetric encryption (AES with an integrity check), and encryption keys are held outside the document store. Automated backups inherit the same encryption.
Where you choose to link outside financial accounts, the connection is made through established aggregation providers. Your institution credentials are entered with the provider, not with us: we never receive or store them. Access granted to us is read-only — the connection cannot be used to trade, move money, or change anything at your institution. You may disconnect a linked account at any time.
Access to client data is limited to personnel who require it to deliver services. Document access, signature events, and administrative actions are written to an append-only, hash-chained audit log designed so that any deletion or modification of a prior entry is detectable.
AI-assisted features operate with a human in the loop and are prohibited from placing trades or moving funds. Where a third-party model provider is used, we seek contractual terms that prohibit training on client data. Client-identifying information is minimized before it is sent to any external model.
We follow financial-industry practice for data security, access control, and network security, and we review and update those policies on an ongoing basis. We are engaging independent security expertise to review our systems. We do not currently hold a SOC 2 or ISO 27001 attestation and do not represent otherwise.
You may request a copy of the personal information we hold about you, request corrections, disconnect linked accounts, or request deletion of your account and associated data, subject to records we are required to retain under securities and tax rules. See the Privacy Policy.
Report suspected vulnerabilities or incidents to security@innovationstratwealth.com. Please do not publicly disclose an issue before we have had a reasonable opportunity to remediate. We do not operate a paid bug-bounty program and cannot offer compensation for reports.