DIY Finance maintains administrative, technical, and physical safeguards designed to protect Member information and service availability.
Security controls may include encryption, access controls, least-privilege permissions, secrets management, audit logging, monitoring, incident response, multi-factor authentication, step-up authentication for higher-risk actions, secure software-development practices, third-party risk management, backup/recovery controls, and network/edge protections.
Authentication strength may increase with the sensitivity or consequence of a Member action. Security architecture may use identity, hosting, network, cloud, observability, and other service providers. Specific vendors and controls may change as the architecture evolves and are not permanent contractual commitments unless expressly stated in an executed agreement.
Public internet traffic may be protected by third-party network and security services, including content-delivery, web-application-firewall, denial-of-service mitigation, bot-management, or related controls.
No system can guarantee absolute security. Members should use reasonable account-security practices and promptly report suspected unauthorized access through the Member Service Center.