Security & Privacy Practices
How Monyra protects your data and maintains security.
1. Overview
At Monyra, security is our top priority. This document describes the technical and organizational measures we implement to protect your financial data and maintain the security of our platform.
2. Encryption
We use 256-bit SSL/TLS encryption for all data transmitted between your device and our servers. Data at rest is encrypted using industry-standard encryption protocols. Your financial data, including credit reports, is encrypted both in transit and at storage.
3. Data Protection
We implement strict data protection measures: (a) access to production data is restricted to authorized personnel only; (b) all data access is logged and audited; (c) sensitive information such as full account numbers and Social Security numbers are redacted before processing; (d) credit report files are stored privately with no public URLs; (e) data is backed up regularly with encrypted backups.
4. Authentication
We use secure authentication mechanisms: (a) passwords are hashed using industry-standard algorithms; (b) we support OAuth providers (Google) for secure login; (c) email verification is required for new accounts; (d) session tokens are securely managed and expire appropriately; (e) multi-factor authentication is available for enhanced security.
5. Account Security
You can enhance your account security by: (a) using a strong, unique password; (b) enabling multi-factor authentication; (c) regularly reviewing your account activity; (d) logging out from shared devices; (e) keeping your contact information up to date for security notifications.
6. Infrastructure Security
Our infrastructure is hosted on secure cloud platforms with: (a) network-level firewalls and intrusion detection; (b) regular security patching and updates; (c) automated vulnerability scanning; (d) DDoS protection; (e) isolated environments for development, staging, and production.
7. Incident Response
We maintain an incident response plan for security events. In the event of a data breach or security incident: (a) we immediately investigate and contain the threat; (b) affected users are notified promptly; (c) we work with security experts to remediate the issue; (d) we report incidents to relevant authorities as required by law.
8. Responsible Disclosure
We welcome security researchers to report vulnerabilities through our responsible disclosure program. If you discover a security issue, please report it through the Contact Legal page with the subject "Security Report." We will acknowledge receipt within 48 hours and work with you to resolve the issue. We do not pursue legal action against good-faith security researchers.
9. Compliance
We comply with applicable data protection regulations including: (a) GDPR (General Data Protection Regulation); (b) CCPA (California Consumer Privacy Act); (c) relevant state and federal privacy laws. We regularly review and update our practices to maintain compliance.
10. Future Certifications
We are working toward additional security certifications including SOC 2 Type II and ISO 27001. These certifications will provide independent verification of our security practices.
11. Contact
For security questions or to report a security issue, please use the Contact Legal page with the subject "Security Report."