Account Security
Comprehensive guide to protecting your account, understanding your data, and how we safeguard your information.
Account Security
At Secure Rise, we employ industry-leading security measures to protect your account from unauthorized access. Our multi-layered security approach ensures your investments and personal information remain safe at all times.
Password Security
- Minimum Requirements: 12+ characters with uppercase, lowercase, numbers, and special characters
- Hashing Algorithm: Passwords hashed using bcrypt with 12-round salt
- No Storage: We never store your actual password, only the secure hash
- Password Strength Meter: Real-time feedback during password creation
- Periodic Reminders: Prompts to update your password every 90 days
- Breach Detection: Automatic checks against known compromised password databases
Two-Factor Authentication (2FA)
- Authenticator Apps: Support for Google Authenticator, Authy, and other TOTP apps
- SMS Verification: Backup option via SMS with one-time codes
- Email Codes: Secondary verification method via email
- Recovery Codes: 10 backup codes for emergency access
- Hardware Keys: Support for YubiKey and other security keys
- Remember Device: Trusted device option for 30 days (optional)
Recommendation: We strongly recommend enabling 2FA for all accounts. Accounts with 2FA enabled are 99.9% less likely to be compromised.
Session Management
- Secure Sessions: HTTP-only, secure, same-site cookies
- Session Timeout: Automatic logout after 30 minutes of inactivity
- Active Sessions View: See all devices currently logged into your account
- Remote Logout: Terminate sessions from any device instantly
- Device Fingerprinting: Detect and alert on new device logins
- IP Monitoring: Track login locations and alert on suspicious activity
Login Security Features
- Rate Limiting: 5 failed attempts triggers 15-minute lockout
- CAPTTCHA Protection: reCAPTCHA v3 on all login attempts
- Biometric Login: Fingerprint and Face ID support on mobile devices
- Login Notifications: Instant email/SMS alerts for new logins
- Geofencing: Optional restriction to specific countries/regions
- Suspicious Activity Detection: AI-powered anomaly detection
Account Recovery
- Secure Recovery: Multi-step verification process for password reset
- Email Verification: Confirmation link sent to registered email
- Security Questions: Optional backup questions for recovery
- Identity Verification: KYC document verification for high-value accounts
- Recovery Window: Reset links expire after 1 hour for security
- Support Escalation: Manual verification by support team when needed
Security Best Practices
- Use a unique password for Secure Rise (never reuse passwords)
- Enable 2FA immediately after account creation
- Never share your password or 2FA codes with anyone
- Be cautious of phishing emails mimicking Secure Rise
- Keep your contact information up to date for recovery
- Review active sessions regularly and remove unknown devices
- Use a password manager to generate and store strong passwords
- Report suspicious activity to support immediately
Account Data
Your account data includes all personal information you provide to Secure Rise. We collect only what's necessary to provide our services and maintain transparency about how your data is used.
Personal Information
- Full Name: Legal name as shown on identification documents
- Date of Birth: Required for age verification and compliance
- Phone Number: For 2FA verification and account recovery
- Email Address: Primary communication and account recovery
- Address: Residential address for KYC and regulatory compliance
- Nationality: Country of citizenship for regulatory purposes
KYC Documentation
- Government ID: Passport, national ID, or driver's license
- Proof of Address: Utility bill, bank statement, or government correspondence
- Selfie Verification: Live photo matching ID document
- Tax Information: Tax identification number where required
- Source of Funds: Declaration of investment fund origin
- Beneficial Ownership: For corporate accounts and high-net-worth individuals
Storage: All KYC documents are encrypted at rest using AES-256 and stored in secure, access-controlled systems. Documents are automatically purged after 5 years of account inactivity.
Financial Information
- Investment Amounts: Record of all deposits and investments
- Withdrawal History: Complete log of all withdrawal requests
- Payment Methods: Linked cryptocurrency wallets and bank accounts
- Transaction History: Detailed record of all financial activities
- ROI Earnings: Accumulated returns and profit distributions
- Balance Information: Current account balances across all currencies
Important: We never store full credit card numbers or banking credentials. Payment processing is handled through PCI DSS compliant third-party providers like Paystack.
Communication Data
- Email History: Copies of transactional emails sent to your account
- Support Tickets: Records of all support interactions
- Marketing Preferences: Your consent status for promotional communications
- Notification Settings: Your preferences for alerts and updates
- SMS Logs: Record of SMS verification codes sent (for security auditing)
Activity & Usage Data
- Login History: Timestamps, IP addresses, and device information
- Page Views: Which sections of the platform you access
- Feature Usage: How you interact with platform features
- Session Duration: Time spent on the platform per session
- Click Patterns: Navigation patterns (for UX improvement)
- Error Logs: Technical errors encountered (for debugging)
Data Access & Export
- Data Export: Download all your data in JSON or CSV format
- Document Download: Access your uploaded KYC documents anytime
- Transaction Reports: Generate detailed financial reports
- Activity Logs: Export your complete account activity history
- Request Processing: Data export requests processed within 24 hours
- Secure Delivery: Exports delivered via encrypted download link
Data Deletion
- Right to Deletion: Request complete deletion of your account and data
- Retention Period: Financial data retained for 7 years (legal requirement)
- Anonymous Data: Usage data anonymized after account deletion
- Deletion Process: Completed within 30 days of request
- Exceptions: Data required for legal proceedings or fraud prevention
- Confirmation: Email confirmation when deletion is complete
Data Storage
Secure Rise utilizes state-of-the-art infrastructure and encryption technologies to store your data securely. Our multi-layered storage architecture ensures your information is protected at every level.
Infrastructure & Hosting
- Cloud Provider: AWS (Amazon Web Services) with enterprise-grade SLA
- Data Centers: Multiple availability zones across different geographic regions
- Redundancy: 99.99% uptime with automatic failover
- Load Balancing: Distributed traffic management for optimal performance
- CDN Integration: CloudFront for fast content delivery worldwide
- Backup Systems: Daily automated backups with 30-day retention
Encryption Standards
- At Rest: AES-256 encryption for all stored data
- In Transit: TLS 1.3 for all data transmissions
- Database: Transparent Data Encryption (TDE) enabled
- File Storage: Encrypted object storage with customer-managed keys
- Key Management: AWS KMS (Key Management Service) for key rotation
- Hashing: bcrypt for passwords, Argon2 for sensitive data
Key Rotation: Encryption keys are automatically rotated every 90 days. All data is re-encrypted with new keys during rotation without service interruption.
Database Architecture
- Primary Database: PostgreSQL with read replicas for performance
- Caching Layer: Redis for fast data access and session management
- Search Engine: Elasticsearch for advanced search capabilities
- Data Sharding: Horizontal scaling for large datasets
- Connection Pooling: Optimized database connection management
- Query Optimization: Regular performance tuning and indexing
Data Isolation & Segregation
- Multi-Tenant Architecture: Logical separation of user data
- Database per Tenant: High-value accounts in isolated databases
- Network Segmentation: VPC with private subnets for database servers
- Firewall Rules: Strict access control between application layers
- API Gateway: Centralized API management with rate limiting
- Service Mesh: Secure service-to-service communication
Backup & Disaster Recovery
- Daily Backups: Automated daily backups at 2:00 AM UTC
- Point-in-Time Recovery: Restore to any moment within 35 days
- Geographic Redundancy: Backups stored in separate AWS regions
- Backup Encryption: All backups encrypted with separate keys
- Restore Testing: Monthly restoration drills to verify integrity
- RPO/RTO: Recovery Point Objective: 1 hour, Recovery Time Objective: 4 hours
Physical Security
- Data Center Access: 24/7 monitored facilities with biometric authentication
- Security Personnel: On-site security teams at all data centers
- Surveillance: Continuous video monitoring with 90-day retention
- Environmental Controls: Fire suppression, climate control, and power redundancy
- Compliance: SOC 2 Type II, ISO 27001, and GDPR certified facilities
- Background Checks: All data center personnel undergo rigorous screening
Network Security
- DDoS Protection: AWS Shield Standard and Advanced protection
- WAF: Web Application Firewall for attack prevention
- IPS/IDS: Intrusion Prevention and Detection Systems
- Private Network: All backend services on private VPC subnets
- VPN Access: Secure VPN for administrative access
- Network Monitoring: Real-time traffic analysis and anomaly detection
Privacy & Protection
Your privacy is fundamental to our business. We implement comprehensive privacy policies and protection measures to ensure your personal information is handled with the utmost care and compliance with global regulations.
Compliance & Certifications
- GDPR: General Data Protection Regulation (EU) compliance
- CCPA: California Consumer Privacy Act compliance
- SOC 2 Type II: Service Organization Control 2 certification
- ISO 27001: Information Security Management System
- PCI DSS: Payment Card Industry Data Security Standard
- AWS Artifact: Third-party compliance documentation available
Data Collection Principles
- Minimization: We collect only data essential for service delivery
- Consent-Based: Explicit consent obtained before data collection
- Transparency: Clear disclosure of what data is collected and why
- Purpose Limitation: Data used only for stated purposes
- Accuracy: Regular data validation and correction processes
- Storage Limitation: Data retained only as long as necessary
Your Privacy Rights
- Right to Access: Request a copy of all your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Portability: Transfer your data to another service
- Right to Object: Object to processing of your data
- Right to Restrict: Limit how we process your data
Exercise Your Rights: Submit privacy requests through your account settings or email privacy@securerise.com. All requests are processed within 30 days.
Data Sharing Policy
- No Selling: We never sell your personal data to third parties
- Service Providers: Limited sharing with essential service providers (payment processors, cloud hosting)
- Legal Requirements: Data disclosed only when required by law
- Business Transfers: Data may transfer in case of merger or acquisition
- Affiliate Sharing: No data sharing with affiliate companies
- Marketing Partners: No data sharing for marketing purposes
Cookie Policy
- Essential Cookies: Required for basic site functionality (always active)
- Analytics Cookies: Help us improve user experience (optional)
- Marketing Cookies: Used for personalized advertising (optional)
- Preference Cookies: Remember your settings and choices
- Cookie Consent: Explicit consent obtained before non-essential cookies
- Cookie Management: Control cookie preferences through settings
Data Breach Response
- Immediate Detection: 24/7 monitoring for security incidents
- Rapid Response: Dedicated incident response team on standby
- Containment: Immediate isolation of affected systems
- Notification: Users notified within 72 hours of breach discovery
- Regulatory Reporting: Timely reporting to relevant authorities
- Post-Mortem: Comprehensive analysis and prevention improvements
Vulnerability Management
- Regular Audits: Quarterly security audits by third-party firms
- Penetration Testing: Annual penetration testing by ethical hackers
- Bug Bounty Program: Responsible disclosure program for security researchers
- Patch Management: Automated security patching within 48 hours
- Dependency Scanning: Continuous monitoring of vulnerable dependencies
- Code Review: Security review for all code changes
Third-Party Links
- Our platform may contain links to third-party websites
- We are not responsible for the privacy practices of external sites
- Review privacy policies of third-party sites before providing information
- Third-party links are provided for convenience and information
- We regularly review linked sites for security and privacy compliance
Security Tips for Users
- Keep your software and browser updated with the latest security patches
- Use reputable antivirus software and keep it current
- Avoid using public Wi-Fi for accessing your account
- Be skeptical of unsolicited emails requesting personal information
- Verify the URL before entering your credentials (look for HTTPS)
- Use a VPN when accessing your account from public networks
- Regularly review your account statements for unauthorized activity
- Report any suspicious emails claiming to be from Secure Rise