Security
You are trusting us with portfolio data. This page states plainly what we do to protect it — no badges we haven't earned, no claims we can't back.
Last updated: July 31, 2026Access control
Zero-trust authentication. The application sits behind Cloudflare Access. Every request is authenticated against your organization's identity policy before it reaches the app — there is no "logged-out but reachable" surface for authenticated routes.
Isolated per-user workspaces. Each user's uploads, scenarios, and run artifacts live in a workspace scoped to that user. One user cannot browse another's data through the application.
Data protection
Encrypted in transit. All traffic is served over TLS.
Encrypted at rest. Stored data is encrypted on disk by the hosting platform.
Minimal surface. The service sets strict security headers (frame denial, content-type sniffing protection, a restrictive permissions policy) and sets no third-party advertising or tracking cookies on the application.
What the application does not do
- It does not connect to your broker or custodian, and it does not move money. It produces trade lists; execution stays with you.
- It does not sell or share your portfolio data. See the Privacy Policy.
Responsible disclosure
If you believe you've found a security issue, email security@rebalanceengine.com. Please include steps to reproduce. We ask that you give us a reasonable window to investigate and remediate before public disclosure; we commit to acknowledging reports within one business day.
Questions
Security questionnaires or architecture questions: hello@rebalanceengine.com.