If you discover a security vulnerability, please email security@invormed.com rather than opening a public issue.
- Never commit API keys or secrets to version control
- Trading 212 and FMP API keys are provided by users and handled locally
- When using the hosted MCP server, API keys are encrypted at rest using AES-256-GCM
- Firebase service account credentials should be stored as environment variables, never in code
- Portfolio data is only accessible by the authenticated user
- Firestore security rules enforce user-level isolation
- No portfolio data is sent to analytics or error tracking services
- Session recordings (Microsoft Clarity) mask all financial data
| Version | Supported |
|---|---|
| 0.1.x | Yes |