Your data is protected in transit by SSL/TLS, and Cloudflare screens traffic at the edge. HSTS is set for one year, but not with includeSubDomains or preload.
A Content-Security-Policy limits where files may load from, though it still allows inline and eval script. We never sell personal information. This page explains the rest: what we store, how it is encrypted, and how long we keep it.
Your data security is our top priority. We implement industry-standard protections to keep your information safe.
Automatic detection and mitigation of distributed denial-of-service attacks at the network edge.
Web Application Firewall
WAF rules protect against common vulnerabilities including SQL injection and cross-site scripting.
Global CDN
Content is served through Cloudflare's global edge network. The size of that network is Cloudflare's figure, not a measurement of ours.
SSL/TLS
Full SSL/TLS encryption for all connections. Certificate management handled automatically.
SSL EnabledHSTS EnabledSecure Headers
How is data encrypted in transit and at rest?
Data in Transit
SSL/TLS encryption for all connections
HTTPS enforced across the entire platform
HTTP Strict Transport Security (HSTS) enabled
Secure session-based authentication
Data at Rest
Neon PostgreSQL with built-in encryption
Encrypted secrets and environment variables
Secure configuration management
No plaintext password storage
Infrastructure Security
Network Security
Cloudflare edge network, firewall rules, IP-based access controls, and rate limiting protect our infrastructure from attacks.
Access Controls
Role-based access, session management, secure authentication, and principle of least privilege for all system access.
Reliability
Managed database backups and health monitoring. Production runs on a single reserved instance — there is no redundant system to fail over to, and saying otherwise would be the easiest claim here to disprove.
What is monitored and logged?
Active Security Monitoring
Security event logging
API abuse detection and rate limiting
Built-in Protection
OAuth state-parameter validation on sign-in
Input sanitization and validation
SQL injection prevention (parameterized queries)
XSS prevention (Content Security Policy)
Bug Bounty and Responsible Disclosure
If you discover a security vulnerability, please report it responsibly. We take all reports seriously and will investigate promptly.
Stock Expert AI uses Cloudflare DDoS protection, Web Application Firewall (WAF), SSL/TLS encryption for all connections, HSTS enforcement, and Content Security Policy headers. Data at rest is encrypted using Neon PostgreSQL's built-in encryption.
Does Stock Expert AI sell user data?
No. Stock Expert AI never sells, rents, or trades personal information to third parties. We follow a privacy-first approach and collect only what is necessary to provide the service.
How can I report a security vulnerability?
If you discover a security vulnerability, please report it responsibly by emailing sedat@stockexpertai.com. We review all reports promptly and take immediate action to address confirmed issues.