Corporate Policy

Information Security Policy

How RW Business Services protects the confidentiality, integrity, and availability of the information it holds — including End User Financial Data obtained via Plaid.

Purpose & scope

Protect the confidentiality, integrity, and availability of RWBS information — especially End User Financial Data obtained via Plaid and stored in RWBS OS. Covers all systems, accounts, devices, code, and third-party services used to run the business.

Roles & responsibilities

The Owner is accountable for information security: setting policy, granting and revoking access, managing vendors, responding to incidents, and the annual review. Security reports and disclosures go to security@rw-businessservices.com (monitored).

Data classification

  • Restricted — End User Financial Data: Plaid access tokens, item/account IDs, bank transactions, balances, statements, receipts. Highest protection; encrypted at rest and in transit; least-privilege access; never logged in plaintext.
  • Confidential: CRM data, business/financial records, secrets and credentials.
  • Internal: operational docs, code.
  • Public: marketing and website content.

Identity & access management

  • MFA everywhere. Phishing-resistant MFA (passkeys, biometrics, or hardware keys where supported) is enabled on every account with access to Restricted or Confidential data: Google Workspace, Vercel, Neon, GitHub, Plaid Dashboard, and the secrets/password manager.
  • Least privilege & unique accounts. Each person or service has its own identity; no shared logins. Access is granted only for a clear business need and revoked promptly when no longer needed.
  • Application auth. RWBS OS is gated by Google OAuth SSO (NextAuth); non-human and machine calls use scoped bearer secrets or OAuth tokens, never shared passwords.
  • Access review. Reviewed at least annually and whenever roles change.

Secrets management

Secrets (API keys, database URLs, FINANCE_ENCRYPTION_KEY, refresh tokens) live only in the platform secret store (Vercel environment variables) and a reputable password manager — never in source code, tickets, or chat. Secret-scanning and push protection are enabled on repositories. Secrets are rotated on suspected exposure and on any staff or vendor change.

Encryption

  • In transit: TLS 1.2+ only for all traffic (Vercel HTTPS with HSTS; Neon, Plaid, and Google APIs are TLS-only).
  • At rest: the financials database (Neon Postgres) is encrypted at rest (AES-256). Plaid access tokens are additionally encrypted at the application layer with AES-256-GCM before storage; the key is held only in the platform secret store. Documents are stored in Google Drive, encrypted at rest by Google.

Endpoint security

Work devices use full-disk encryption (FileVault), automatic OS and security updates, a screen lock with a short timeout, and a supported OS version. Devices are not shared.

Vulnerability & patch management

  • Automated dependency scanning (GitHub Dependabot) plus npm audit; known-exploitable vulnerabilities are triaged and patched promptly.
  • Platform, OS, and managed-service patching is handled by the vendors (Vercel, Neon, Google) and by endpoint auto-update.

Secure development

  • Private repositories only; changes ship through the /deploy review gates (automated reviewers and build) before production.
  • No secrets in code; input from external sources is sanitized; the Google Sheets layer uses RAW writes to prevent formula injection; the ledger enforces double-entry integrity at the database.

Vendor & subprocessor management

Restricted and Confidential data is entrusted only to reputable providers with their own security programs: Vercel (hosting), Neon (database), Google (auth, Drive, Sheets), Plaid (bank data), Resend (email), and Anthropic (AI). New subprocessors are reviewed before adoption.

Logging & monitoring

Security-relevant changes to financial data are recorded in an append-only audit log, immutable at the database. Platform logs (Vercel) are available for investigation. Access to the Plaid Dashboard and production systems is limited and monitored.

Incident response & breach notification

On a suspected security incident:

  1. Contain — rotate affected secrets and FINANCE_ENCRYPTION_KEY, and invalidate exposed Plaid tokens via /item/access_token/invalidate.
  2. Assess scope using the audit log and platform logs.
  3. Notify Plaid promptly at security@plaid.com for any breach or unauthorized use of End User Data.
  4. Notify other affected parties and regulators as required by law.
  5. Remediate and record lessons learned.

Data retention & deletion

Governed by the Data Retention & Deletion Policy, including deletion of Plaid data on disconnect via /item/remove.

Risk management & review

The Owner reviews risks and this policy at least annually, updating controls as the business grows — notably enabling per-tenant isolation and MFA-before-Link before offering the product to external customers.

Acceptable use

Company systems and data are used only for legitimate business purposes and in line with this policy and applicable vendor terms.

ContactRW Business Services, LLC
security@rw-businessservices.com
South Lake Tahoe, California 96150
RW Business Services, LLCInformation Security PolicyVersion 1.0 · Effective July 30, 2026