Security
Security
Last updated: [DATE]
Draft pending legal review. This text is not final.
Contents
Journey handles compensation, benefits, equity, and financial data. Protecting it is a design constraint, not a feature. This page describes how, in plain terms.
Infrastructure
Journey is hosted on established cloud infrastructure providers including [Vercel, Supabase, and Cloudflare — CONFIRM naming with Tiago]. Our marketing and product environments use separate data stores and access boundaries.
Encryption
Data is encrypted in transit and at rest. [CONFIRM the broad claim holds across providers; do not publish version/algorithm specifics — those live in security questionnaires, not here.]
Access controls
Access to Journey is protected through secure authentication and role-based access controls. Internal access to customer information is limited by least-privilege principles and operational need. [IF TRUE, add: “Administrative access is protected by multi-factor authentication and logged.” This sentence carries the section — only publish it verified.]
Data boundaries
The employer–employee data boundary — what your employer can and cannot see — is defined precisely in our Privacy Policy. It is enforced in the product’s architecture, not just in policy.
Financial account connections are read-only. Journey retrieves transactions, investments, and liabilities data only; payment products are excluded, and Journey cannot move money. Connections are handled by established aggregation providers — you can read how [Plaid protects your data → link Plaid’s trust/security page; add MX / Finicity-or-Yodlee equivalents as each ships].
You can also connect your own equity accounts [e.g., Carta → name + link when the employee-side connection is live]. These connections are read-only: Journey retrieves your equity records and cannot transact.
Your employer’s HR, payroll, and equity systems connect through established integration providers, authorized by your employer, with read-only access.
[CONFIRM: enabled products/scopes across ALL aggregation providers — Plaid, MX, Finicity or Yodlee — match the enumeration exactly; employee-side Carta connection live or planned (name only when shipped), and its exact OAuth scopes verified before “read-only / cannot transact” publishes — same standard as Plaid; employer-side integrations (Finch, Carta issuer) read-only as stated. Equity connected via an employee’s personal account — including prior-employer equity — is personal-side data under the Privacy Policy’s visibility promise; confirm the architecture enforces that the current employer never sees it.]
AI and data
Journey uses third-party AI model providers under contracts restricting their use of your data. We do not permit them to train their models on your data. [VERIFY across every path before publish: each model provider’s API data controls, any fallback/provider routing, any observability or proxy tooling that can see prompts, and retention configurations. If all consistent, publish the strong claim; if not, fix the stack, don’t weaken the sentence.]
Reliability and recovery
Journey maintains backups and recovery procedures designed to protect against accidental loss or service disruption. [CONFIRM backup and recovery posture before publish.]
Security program
Journey maintains an ongoing security and compliance program using automated monitoring and control-management tooling. [CONFIRM tooling claim. No SOC 2 mention until readiness/audit has actually begun — then “working toward SOC 2 Type I,” and only what’s accurate.]
Reporting a vulnerability
If you believe you’ve found a security issue, email security@usejourneywealth.com. We take security reports seriously and investigate reported issues promptly. [COUNSEL, later: formal responsible-disclosure policy with safe-harbor language — separate page when warranted, not a launch blocker.]
Questions
Security reviews are welcome. Employers evaluating Journey can reach us at security@usejourneywealth.com.