Cybersecurity Policy

Effective as of June 16, 2026.

Vibetrade maintains administrative, technical, and organizational safeguards designed to protect the Vibetrade app, website, production systems, corporate workstations, customer data, and broker-connection workflows. This policy summarizes our current security program for customers, partners, and vendors.

Data Classification and Handling

We classify data based on sensitivity and business impact:

  • Public data: marketing pages, public documentation, and other information approved for public release.
  • Internal data: non-public business information, operational notes, product plans, and internal metrics.
  • Confidential data: customer account data, support communications, diagnostics tied to a user, authentication records, broker-connection metadata, and security logs.
  • Restricted data: secrets, API keys, broker OAuth tokens, production credentials, private signing material, and incident response materials.

Access, storage, transmission, logging, and retention rules are based on classification. Confidential and restricted data must be stored only in approved systems, must not be copied into unmanaged files or personal accounts, and must not be exposed in logs, screenshots, analytics events, support tickets, or debugging artifacts unless specifically approved for security or support handling.

Access Control and Privileged Access Management

Access to production systems is limited to authorized personnel with a business need. We use least-privilege access, role-based permissions where supported, and separate access scopes for development, staging, production, billing, vendor administration, and security-sensitive systems.

Privileged access must use strong authentication and is reviewed periodically. Production secrets are managed through approved secret-management systems and are not committed to source control. Access is removed or rotated when personnel responsibilities change, when vendor access is no longer needed, or when compromise is suspected.

Encryption of Data at Rest and in Transit

Vibetrade uses HTTPS/TLS for data transmitted between users, Vibetrade services, and supported third-party services. Broker authorization flows use provider-supported secure authorization mechanisms and do not require Vibetrade to store broker login passwords.

Production databases, managed storage, secrets, and backups are encrypted at rest where supported by the underlying platform. Restricted secrets and tokens are stored only in approved systems designed for secret storage or encrypted managed data storage.

Vulnerability Management and Patch Management

We monitor application dependencies, infrastructure configuration, and platform updates for vulnerabilities. Security updates are prioritized based on severity, exploitability, exposure, and customer impact.

Application code changes are reviewed and validated through type checks, linting, tests, and deployment controls appropriate to the affected system. Critical or actively exploited vulnerabilities are triaged promptly and remediated through patching, configuration changes, dependency updates, credential rotation, feature disablement, or other compensating controls.

Incident Response and Disaster Recovery

Security incidents are triaged based on severity, affected systems, data classification, customer impact, and regulatory or contractual obligations. Response activities may include containment, credential rotation, log review, vendor coordination, customer notification, forensic preservation, remediation, and post-incident review.

Vibetrade uses managed infrastructure and backups where available to support recovery from service disruption, data loss, or platform failure. Recovery priorities are based on protecting customer data, restoring authentication and broker-connection safety, and resuming core service availability.

Physical Security

Vibetrade does not operate public customer workloads from company-owned data centers. Production systems are hosted with cloud and managed infrastructure providers that maintain physical security controls for their facilities.

Corporate devices must use operating-system login protection, screen lock, disk encryption where supported, and remote wipe or account revocation when a device is lost, stolen, or retired.

Vendor Risk Management

Vibetrade uses third-party vendors for hosting, authentication, observability, payments, brokerage connectivity, communications, and operational tooling. Vendors are evaluated based on the type of data processed, system criticality, security posture, access requirements, and contractual obligations.

Vendors that process confidential or restricted data must use appropriate security controls, and access is limited to the minimum required for the service. Vendor access is reviewed when services are added, materially changed, or discontinued.

Network Endpoint Protection Against Malicious Code

Vibetrade protects production and corporate endpoints against malicious code through layered controls:

  • Production servers and managed runtime: production workloads run on managed cloud/serverless platforms with restricted administrative access, minimal exposed services, provider-managed infrastructure patching, isolated deployments, secret-managed configuration, and monitored logs. We do not allow general-purpose browsing, email, or unmanaged software installation on production runtime environments.
  • Corporate workstations: workstations use current operating-system security updates, built-in malware protection or equivalent endpoint protection, browser and email hygiene, disk encryption where supported, device lock policies, and restricted access to production credentials.
  • Source and dependency controls: code and dependency changes are reviewed, scanned or validated through automated checks where available, and deployed through controlled build paths.
  • Credential controls: access tokens, API keys, and broker-related secrets are stored in approved secret systems and rotated when compromise is suspected.
  • Detection and response: suspicious endpoint, repository, production, or vendor activity is investigated and may trigger account revocation, credential rotation, device isolation, or deployment rollback.

Employee and Contractor Responsibilities

Personnel with access to Vibetrade systems must protect credentials, use approved devices and tools, report suspected phishing or compromise, avoid storing restricted data outside approved systems, and follow incident escalation procedures.

Contact

To report a security concern, contact security@tryvibetrade.com.