Trust

Data Security Policy

The controls MyFinancialAdvisory uses to protect your documents and business data — private storage, tenant isolation, least-privilege access and audit logging.

Last updated: June 2026

1.Our approach

Security is built into how the platform works, not added on top. This policy summarises the main controls we use to protect your documents and business data. It is written in plain language; some specifics are kept general to avoid revealing information that could help an attacker.

2.Private document storage

Documents you upload are stored in private buckets — never as public links. Files are served through short-lived, signed access that expires, so a link cannot be shared or reused indefinitely. Raw storage paths are not exposed.

3.Tenant isolation

Each organisation’s data is logically isolated. Database access is governed by row-level security so a user can only read or change records belonging to organisations they are a member of, with the role they hold. Cross-organisation access is denied by default.

4.Least-privilege access

  • Team members see only what their role permits within an organisation.
  • Server-side administrative access is scoped to the specific tables and operations it needs — never blanket access.
  • Sensitive keys are kept server-side and are never shipped to the browser.

5.Encryption and transport

Traffic between your browser and the platform is encrypted in transit using HTTPS. Credentials and session tokens are handled using established authentication mechanisms.

6.Audit logging

Important actions — including document access and downloads — are recorded in append-only audit logs. This supports accountability and helps us investigate any unusual activity.

7.AI and your data

AI features assist with checks and explanations. We do not use your private documents to train third-party public models, and AI does not replace the professional review applied before filing.

8.Reporting a vulnerability

If you believe you have found a security issue, please email info@myfinancialadvisory.com with details. We appreciate responsible disclosure and will work to address valid reports promptly.

9.Your part

  • Use a strong, unique password and keep it private.
  • Only invite team members who genuinely need access, with the right role.
  • Tell us immediately if you suspect unauthorised access to your account.

This page is provided for general information and transparency. It is not legal advice. For specific concerns about your account or data, please contact our team.