DIY Finance’s enterprise security program is intended to protect confidentiality, integrity, availability, and appropriate use of Member and enterprise information.
Security domains
- Identity and access management, including least privilege and role-based controls.
- Multi-factor and risk-based authentication for higher-risk administrative access.
- Encryption in transit and at rest where appropriate.
- Secrets and key management.
- Secure software-development lifecycle, code review, dependency management, and vulnerability remediation.
- Environment separation and change control.
- Logging, monitoring, alerting, and incident response.
- Backup, recovery, and business-continuity planning.
- Network and edge protections for public-facing traffic.
- Third-party and subprocessor risk management.
- Sensitive-data minimization in logs, analytics, support systems, and automated-system payloads.
Security descriptions should remain accurate and should not promise specific certifications, technologies, response times, or vendors unless those commitments are current, verified, and contractually approved.