Trust & Security

Security & Compliance

How FlashAlpha hosts, secures, and operates the service - an honest overview for enterprise due diligence. We state our current posture plainly and label what is Enterprise-scoped rather than imply attestations we do not yet hold.

Updated 2026-06-13 Live status flashalpha.com/status Security contact [email protected]

Hosting & infrastructure

  • Region. The service runs on dedicated servers in the EU (Germany).
  • Edge. Cloudflare sits in front of every public endpoint, providing TLS termination, DDoS mitigation, and a web application firewall.
  • Transport. All traffic is served over HTTPS (TLS 1.2+); plaintext HTTP is redirected to HTTPS.

Data we hold - and don't

  • Account data. Email, a hashed password (ASP.NET Identity), an API key, and request/usage logs.
  • Billing. Payments are processed by Stripe; we store only Stripe references (customer and subscription IDs). No card data touches our servers - cardholder data is handled entirely by Stripe (PCI DSS Level 1).
  • Product data. FlashAlpha is a computed-analytics layer over the public US listed-options market. We do not hold customer trading positions, portfolios, order flow, or brokerage credentials.

Encryption & access

  • In transit. TLS 1.2+ end-to-end (Cloudflare edge and origin).
  • At rest. Application and market data reside on access-controlled servers in EU data centres; database credentials are injected from host-local secrets and are not embedded in client-facing code.
  • Authentication. REST access uses a per-account X-Api-Key; the MCP server additionally supports OAuth 2.1 (PKCE + dynamic client registration). Administrative surfaces are separately authenticated.
  • Access control & abuse. Per-user daily request quotas (HTTP 429 + Retry-After on exhaustion) and tiered entitlements gate what each key can read.

Availability & resilience

  • Transparency. A public system status page reports live component status and 90-day uptime - API, market-data feed, and historical service - measured by an independent external monitor over the real request path, so a genuine outage is recorded even when a service cannot self-report.
  • Backups & recovery. The primary databases are backed up on a regular schedule with copies kept off the primary host; restore is the disaster-recovery path.
  • SLA. Standard tiers are best-effort; a contractual uptime SLA is available under Enterprise agreements.

Privacy & compliance

  • GDPR. Data is EU-hosted and handled in line with GDPR principles; data-processing terms and formal data-residency commitments are available under Enterprise agreements. See Privacy, Terms, and Risk disclosure.
  • Current attestation status. FlashAlpha is not currently SOC 2 or ISO 27001 certified. We state that plainly rather than imply a certification we do not hold. Formal attestations, security questionnaires, and data-residency guarantees are handled as Enterprise-scoped engagements.

Subprocessors

The third parties involved in operating the service:

  • Hosting - EU dedicated-server provider (Hetzner, Germany).
  • Cloudflare - CDN, TLS, DDoS/WAF at the edge.
  • Stripe - billing and payment processing.
  • Email provider - account and transactional email.
  • Upstream market-data providers - market data only; no customer data is shared with them.
Reporting a vulnerability. Email [email protected] with details and reproduction steps; we will acknowledge and remediate. Enterprise security reviews, questionnaires (incl. SOC 2 / ISO 27001 / data-residency scoping), and SLAs are handled via commercial enquiry.

This overview describes the current operational posture and is updated as that posture changes; it is not a contract. Enterprise commitments are set out in the applicable agreement.

Ready to build?

Get your free API key and start pulling live options data in 30 seconds.

Get Free API Key Try Playground