Security
Last updated: [DATE — awaiting legal approval]
Infrastructure
[LEGAL REVIEW REQUIRED] NEI Invest Suite runs on AWS EC2 with encrypted EBS volumes, automated snapshots, and DLM lifecycle policies.
Data Encryption
[LEGAL REVIEW REQUIRED] All data in transit uses TLS 1.2+. Exchange API keys are encrypted at rest. Database connections require authentication.
Authentication
[LEGAL REVIEW REQUIRED] Passwords are hashed using Werkzeug/bcrypt. Sessions expire after inactivity. Future: 2FA support planned.
API Key Handling
[LEGAL REVIEW REQUIRED] Your exchange API keys are encrypted before storage. We recommend using read-only or trade-only permissions with IP whitelisting on your exchange.
Reporting Vulnerabilities
If you discover a security vulnerability, please report it to: info@nietoengineeringinc.com. Do not publicly disclose vulnerabilities before they are resolved.