DIY Finance

Enterprise

Security Practices

Version 2.2Effective September 9, 2026Contact: security@diyfinance.app

DIY Finance’s enterprise security program is intended to protect confidentiality, integrity, availability, and appropriate use of Member and enterprise information.

Security domains

  • Identity and access management, including least privilege and role-based controls.
  • Multi-factor and risk-based authentication for higher-risk administrative access.
  • Encryption in transit and at rest where appropriate.
  • Secrets and key management.
  • Secure software-development lifecycle, code review, dependency management, and vulnerability remediation.
  • Environment separation and change control.
  • Logging, monitoring, alerting, and incident response.
  • Backup, recovery, and business-continuity planning.
  • Network and edge protections for public-facing traffic.
  • Third-party and subprocessor risk management.
  • Sensitive-data minimization in logs, analytics, support systems, and automated-system payloads.

Security descriptions should remain accurate and should not promise specific certifications, technologies, response times, or vendors unless those commitments are current, verified, and contractually approved.