This page summarizes the security practices Treasurium AI Labs Corp applies when working with customers, including those in finance-adjacent and crypto-adjacent contexts. It describes practices; it does not claim any specific third-party certification unless explicitly stated below.
1. Encryption
- In transit: Traffic to and from our public services is encrypted using TLS 1.2 or higher.
- At rest: Data stored on our behalf by cloud infrastructure providers is encrypted at rest using industry-standard algorithms managed by those providers.
2. Access controls
- Access to production systems is limited to authorized personnel on a least-privilege basis.
- Multi-factor authentication is required for access to administrative consoles and code-hosting.
- Access is reviewed periodically and revoked promptly when no longer needed.
3. Application security
- Row-level security and role-based access controls are used to separate customer data at the database layer where applicable.
- Secrets and API keys are stored in managed secret storage and are not hard-coded in application source or client-side code.
- Dependencies are monitored for known vulnerabilities and updated on a regular cadence.
4. Vendor due diligence
We assess sub-processors and cloud providers based on their security posture, contractual commitments, and applicable regional data-handling requirements. Customer-facing sub-processors are subject to written agreements that require them to protect customer data.
5. Logging and monitoring
Production systems generate audit and application logs used for security monitoring and incident investigation. Retention periods are set to balance security needs with data minimization.
6. Backup and continuity
Databases used to host customer data are backed up by our cloud providers on a routine schedule, and we maintain procedures to restore service in the event of a disruption.
7. Incident response
We maintain internal procedures for detecting, triaging, and responding to security incidents. If a security incident materially affects customer data, we will notify the affected customer(s) in accordance with applicable law and our contractual commitments.
8. Certifications
Treasurium does not currently hold formal third-party attestations such as SOC 2 or ISO 27001. Any such certifications will be listed here only after they are formally issued. Enterprise customers may request our current security overview and questionnaires by contacting contact@treasurium.ai.
9. Reporting a vulnerability
If you believe you have found a security vulnerability in our website or services, please email contact@treasurium.ai. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.