Skip to main content
Stock Expert AI
Security First

Your Data is Protected

Your data is protected in transit by SSL/TLS, and Cloudflare screens traffic at the edge. HSTS is set for one year, but not with includeSubDomains or preload.

A Content-Security-Policy limits where files may load from, though it still allows inline and eval script. We never sell personal information. This page explains the rest: what we store, how it is encrypted, and how long we keep it.

Your data security is our top priority. We implement industry-standard protections to keep your information safe.

How does Cloudflare protect the platform?

Our entire infrastructure sits behind Cloudflare's security network.

DDoS Protection

Automatic detection and mitigation of distributed denial-of-service attacks at the network edge.

Web Application Firewall

WAF rules protect against common vulnerabilities including SQL injection and cross-site scripting.

Global CDN

Content is served through Cloudflare's global edge network. The size of that network is Cloudflare's figure, not a measurement of ours.

SSL/TLS

Full SSL/TLS encryption for all connections. Certificate management handled automatically.

SSL Enabled HSTS Enabled Secure Headers

How is data encrypted in transit and at rest?

Data in Transit

  • SSL/TLS encryption for all connections
  • HTTPS enforced across the entire platform
  • HTTP Strict Transport Security (HSTS) enabled
  • Secure session-based authentication

Data at Rest

  • Neon PostgreSQL with built-in encryption
  • Encrypted secrets and environment variables
  • Secure configuration management
  • No plaintext password storage

Infrastructure Security

Network Security

Cloudflare edge network, firewall rules, IP-based access controls, and rate limiting protect our infrastructure from attacks.

Access Controls

Role-based access, session management, secure authentication, and principle of least privilege for all system access.

Reliability

Managed database backups and health monitoring. Production runs on a single reserved instance — there is no redundant system to fail over to, and saying otherwise would be the easiest claim here to disprove.

What is monitored and logged?

Active Security Monitoring

  • Security event logging
  • API abuse detection and rate limiting

Built-in Protection

  • OAuth state-parameter validation on sign-in
  • Input sanitization and validation
  • SQL injection prevention (parameterized queries)
  • XSS prevention (Content Security Policy)

Bug Bounty and Responsible Disclosure

If you discover a security vulnerability, please report it responsibly. We take all reports seriously and will investigate promptly.

Security Email: sedat@stockexpertai.com

Your Role in Security

Strong Password

Use a strong, unique password with a mix of letters, numbers, and symbols.

Unique Password

Don't reuse passwords from other sites. Use a password manager to keep track.

Beware of Phishing

We'll never ask for your password via email. Verify URLs before entering credentials.

Keep Software Updated

Keep your browser and operating system updated with the latest security patches.

Security Headers Implemented

Strict-Transport-Security
max-age=31536000 (one year). Subdomains and preload are NOT included — stated because you can check it in one request.
X-Frame-Options
SAMEORIGIN — our own pages may frame each other; third-party framing is blocked
X-Content-Type-Options
nosniff — prevents MIME sniffing
Content-Security-Policy
Restricts resource origins. Inline and eval script are still permitted, so this is not a strict CSP.
Referrer-Policy
strict-origin-when-cross-origin
Permissions-Policy
Restricts browser feature access

Security References

Frequently Asked Questions

How does Stock Expert AI protect user data?

Stock Expert AI uses Cloudflare DDoS protection, Web Application Firewall (WAF), SSL/TLS encryption for all connections, HSTS enforcement, and Content Security Policy headers. Data at rest is encrypted using Neon PostgreSQL's built-in encryption.

Does Stock Expert AI sell user data?

No. Stock Expert AI never sells, rents, or trades personal information to third parties. We follow a privacy-first approach and collect only what is necessary to provide the service.

How can I report a security vulnerability?

If you discover a security vulnerability, please report it responsibly by emailing sedat@stockexpertai.com. We review all reports promptly and take immediate action to address confirmed issues.

For more details on how we handle your information, please review our Privacy Policy and Disclaimer. Questions? Contact us.