Effective Date: January 4, 2026 | Last Updated: January 4, 2026 | Version: 1.0
This Information Security Policy establishes the framework for protecting the confidentiality, integrity, and availability of financial data processed by Iris Secure Financial. This policy applies to all systems, applications, and personnel handling customer financial information.
Security Contact:
This policy covers:
User Authentication (NextAuth.js):
Multi-Factor Authentication (MFA):
Data in Transit:
Data at Rest:
Highly Sensitive: Bank account credentials (handled by Plaid, never stored), financial transaction details, authentication tokens
Sensitive: Personal information, business financial data, organizational settings
Internal: System logs (sanitized), application metadata
Security Incidents:
Process:
Critical Vendors:
Assessment Process:
See our Data Retention Policy for retention details.
Roadmap for 2026:
Document Version: 1.0
Next Review Date: January 4, 2027
Approved By: Support Team
Distribution: Internal use, available to partners/auditors upon request