EveryIntel

Trust

Security

EveryIntel is built as future financial-data infrastructure. This page states plainly what is in place today and what is not.

In place today

  • Transport: HTTPS only, HSTS, modern TLS at the edge.
  • Browser hardening: strict Content Security Policy with per-request script nonces, frame denial, no MIME sniffing, restrictive permissions policy.
  • Authentication: administrative access requires a strong password (scrypt-hashed) and a time-based one-time code (TOTP). Sessions are server-side, short-lived, bound to secure cookies and revocable.
  • Brute-force protection: per-account and per-address throttling with progressive lockout.
  • Authorisation: role-based access (owner, admin, analyst, viewer) checked on every server action.
  • Database: application data lives in a schema not exposed to the public data API; row-level security is enforced on every table; all queries are parameterised.
  • API keys: stored only as SHA-256 hashes, scoped, rate-limited, individually revocable and rotatable.
  • Webhooks and schedulers: signature or secret verification with constant-time comparison.
  • Audit: administrative actions, logins and collector runs are written to an append-only audit log.
  • Secrets: held only in the hosting provider’s encrypted environment; never in source control; automated secret scanning.
  • Supply chain: dependency vulnerability scanning on every change.

Not yet in place

  • EveryIntel does not hold SOC 2, ISO 27001 or any other certification. We will not claim one until an independent audit is complete.
  • No independent penetration test has been performed yet.
  • Single sign-on (SAML/OIDC) for customer organisations is planned, not available.

Reporting a vulnerability

Please report suspected vulnerabilities through the contact form with the topic “Security”. We ask that you do not access data that is not yours, degrade the service, or disclose the issue publicly before we have had a reasonable chance to fix it. A machine-readable policy is published at /.well-known/security.txt.