Trust & Security
Security & Compliance
How FlashAlpha hosts, secures, and operates the service - an honest overview for enterprise due diligence. We state our current posture plainly and label what is Enterprise-scoped rather than imply attestations we do not yet hold.
Hosting & infrastructure
- Region. The service runs on dedicated servers in the EU (Germany).
- Edge. Cloudflare sits in front of every public endpoint, providing TLS termination, DDoS mitigation, and a web application firewall.
- Transport. All traffic is served over HTTPS (TLS 1.2+); plaintext HTTP is redirected to HTTPS.
Data we hold - and don't
- Account data. Email, a hashed password (ASP.NET Identity), an API key, and request/usage logs.
- Billing. Payments are processed by Stripe; we store only Stripe references (customer and subscription IDs). No card data touches our servers - cardholder data is handled entirely by Stripe (PCI DSS Level 1).
- Product data. FlashAlpha is a computed-analytics layer over the public US listed-options market. We do not hold customer trading positions, portfolios, order flow, or brokerage credentials.
Encryption & access
- In transit. TLS 1.2+ end-to-end (Cloudflare edge and origin).
- At rest. Application and market data reside on access-controlled servers in EU data centres; database credentials are injected from host-local secrets and are not embedded in client-facing code.
- Authentication. REST access uses a per-account
X-Api-Key; the MCP server additionally supports OAuth 2.1 (PKCE + dynamic client registration). Administrative surfaces are separately authenticated. - Access control & abuse. Per-user daily request quotas (HTTP 429 +
Retry-Afteron exhaustion) and tiered entitlements gate what each key can read.
Availability & resilience
- Transparency. A public system status page reports live component status and 90-day uptime - API, market-data feed, and historical service - measured by an independent external monitor over the real request path, so a genuine outage is recorded even when a service cannot self-report.
- Backups & recovery. The primary databases are backed up on a regular schedule with copies kept off the primary host; restore is the disaster-recovery path.
- SLA. Standard tiers are best-effort; a contractual uptime SLA is available under Enterprise agreements.
Privacy & compliance
- GDPR. Data is EU-hosted and handled in line with GDPR principles; data-processing terms and formal data-residency commitments are available under Enterprise agreements. See Privacy, Terms, and Risk disclosure.
- Current attestation status. FlashAlpha is not currently SOC 2 or ISO 27001 certified. We state that plainly rather than imply a certification we do not hold. Formal attestations, security questionnaires, and data-residency guarantees are handled as Enterprise-scoped engagements.
Subprocessors
The third parties involved in operating the service:
- Hosting - EU dedicated-server provider (Hetzner, Germany).
- Cloudflare - CDN, TLS, DDoS/WAF at the edge.
- Stripe - billing and payment processing.
- Email provider - account and transactional email.
- Upstream market-data providers - market data only; no customer data is shared with them.
Reporting a vulnerability. Email [email protected] with details and reproduction steps; we will acknowledge and remediate. Enterprise security reviews, questionnaires (incl. SOC 2 / ISO 27001 / data-residency scoping), and SLAs are handled via commercial enquiry.
This overview describes the current operational posture and is updated as that posture changes; it is not a contract. Enterprise commitments are set out in the applicable agreement.