Security
This page summarizes the current security posture of Alpha Portfolio in practical terms. It is intentionally conservative and should not be read as a certification or guarantee.
1. Secure sign-in with Google
Alpha Portfolio currently uses Google authentication for account access. Keeping your Google account protected is an important part of securing access to the service.
2. Account-scoped data access
The product is designed so that portfolio, account, transaction, and derived holdings data are associated with the signed-in user account rather than being shared publicly.
3. Reasonable technical and organizational measures
We use practical safeguards intended to reduce unauthorized access, abuse, and common web security risks. Measures may evolve as the product matures.
4. Storage and protection language
Certain application data and session-related information are stored using standard SaaS infrastructure and product controls. This page does not claim certifications or controls that have not been formally implemented or verified.
5. No custody or trading authority
Alpha Portfolio does not hold customer funds, execute trades, or provide custody over brokerage or exchange accounts.
6. Responsible disclosure
To report a suspected security issue, contact [SECURITY_EMAIL]. Please provide clear reproduction details and avoid public disclosure until the issue has been reviewed.