Vaultfy
ALFRED SERVICES PRIORITY ACCESS CONTACT
DOWNLOAD APP
Legal

Security Policy

Fortress Edition
Effective Date: 20 August 2026 · Version 2.0

VAULTFY AI TRADING CO LTD (hereinafter referred to as "We," "Us," or "Our"), Company No. 17156633, with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, is unequivocally committed to establishing and maintaining an Institutional Fortress of security for all information assets. This Security Policy (the "Policy") outlines the advanced principles, stringent responsibilities, and robust controls implemented to safeguard Our FinTech infrastructure platform and ultra-luxury concierge orchestration service (the "Service").

This policy is designed to exceed industry best practices, aligning with and often surpassing standards such as ISO 27001, NIST Cybersecurity Framework, SOC 2 Type II, and PCI-DSS Level 1 equivalent controls, while ensuring strict compliance with all relevant data protection and financial services regulations (e.g., UK GDPR, FCA guidelines).

1. Scope and Unwavering Applicability

This Policy applies to all VAULTFY.AI employees, contractors, third-party service providers, and any individuals or entities who access, process, or manage VAULTFY.AI information assets or systems. It covers all information, whether in digital, physical, or verbal form, and all systems, networks, and applications used to deliver the Service, including but not limited to ALFRED AI, hybrid payment rails, and client data.

2. Foundational Information Security Principles

VAULTFY.AI operates on the following non-negotiable information security principles:

  • Confidentiality: Absolute protection of sensitive information from unauthorized disclosure, ensuring client privacy and proprietary data integrity.
  • Integrity: Guaranteeing the accuracy, completeness, and authenticity of all information, preventing unauthorized modification or destruction.
  • Availability: Ensuring timely, reliable, and resilient access to information and systems for authorized users, even in the face of adverse events.
  • Accountability: Establishing clear ownership and audit trails for all actions related to information security.
  • Compliance: Unwavering adherence to all applicable laws, regulations, and contractual obligations, with continuous monitoring of the evolving threat and regulatory landscape.

3. Governance, Oversight, and Unambiguous Responsibilities

3.1. Chief Information Security Officer (CISO)

VAULTFY.AI has appointed a dedicated Chief Information Security Officer (CISO) with executive authority, responsible for:

  • Strategic development, implementation, and continuous improvement of the Information Security Management System (ISMS).
  • Overseeing compliance with this Policy, regulatory requirements, and industry standards.
  • Leading security incident response, threat intelligence, and advanced risk assessments.
  • Reporting directly to the Board of Directors on security posture and risk.

3.2. Employee and Contractor Responsibilities

All personnel are mandated to:

  • Strictly adhere to this Security Policy and all associated procedures.
  • Complete rigorous, ongoing security awareness and specialized training.
  • Immediately report any suspected security incidents, vulnerabilities, or policy violations.
  • Act as custodians of VAULTFY.AI information assets, protecting them with the highest diligence.

4. Data Protection, Privacy, and Aggressive Minimization

4.1. Granular Data Classification

All information assets are classified with granular detail based on their sensitivity and criticality (e.g., Public, Internal, Confidential, Restricted, Top Secret). Access controls and protection measures are meticulously applied according to this classification, with a bias towards the highest level of protection.

4.2. End-to-End Data Encryption

  • Data at Rest: All sensitive client data, financial records, proprietary code, and system configurations are encrypted at rest using FIPS 140-2 validated modules and AES-256 or stronger algorithms.
  • Data in Transit: All data transmitted over internal and external networks is encrypted using TLS 1.3 or stronger protocols, with perfect forward secrecy (PFS) enforced.
  • Secrets on Your Device: On-device secrets are held in the platform secure enclave/keystore via secure storage. Authentication tokens are never written to plain application preferences.

4.3. Data Minimization and Immutable Retention

We implement aggressive data minimization strategies, collecting and retaining only the absolute minimum personal data necessary for the provision of the Service and for strict compliance with legal and regulatory obligations. Data retention periods are immutably defined and enforced, with secure deletion or anonymization upon expiry.

5. Advanced Access Control and Identity Management

5.1. Zero Trust Architecture

VAULTFY.AI operates on a Zero Trust security model, where no user or device is inherently trusted, regardless of their location. All access requests are authenticated, authorized, and continuously validated.

5.2. Multi-Factor Authentication (MFA) and Biometrics

MFA is mandatory for all internal systems, administrative access, and client access to sensitive features. Biometric authentication (Face ID / Touch ID / fingerprint) is offered to unlock or protect the app; it is performed on-device by the operating system, and We never receive or store your biometric templates.

5.3. Principle of Least Privilege and Just-in-Time Access

Access to information systems and data is strictly granted based on the principle of least privilege and, where feasible, Just-in-Time (JIT) access, ensuring temporary permissions for specific tasks.

5.4. Privileged Access Management (PAM)

Robust PAM solutions are deployed to control, monitor, and audit all privileged accounts and activities, preventing unauthorized elevation of privileges.

6. Network, System, and Cloud Security

6.1. Micro-Segmentation and Software-Defined Networking (SDN)

Our network infrastructure utilizes micro-segmentation and SDN to isolate critical systems and data at the workload level, dramatically limiting the blast radius of any potential security breaches.

6.2. Advanced Threat Protection (ATP)

Next-generation firewalls (NGFW), Intrusion Detection/Prevention Systems (IDPS), and Security Information and Event Management (SIEM) systems are deployed for continuous monitoring, threat detection, and automated response to malicious activities.

6.3. Continuous Vulnerability Management and Red Teaming

  • Automated Scans: Continuous, automated vulnerability scans and rigorous penetration tests are conducted on all systems and applications by independent, CREST-certified third parties.
  • Red Team Exercises: Regular red team exercises simulate real-world attacks to identify and remediate weaknesses in defenses.
  • Patch Management: A highly automated and prioritized patch management process ensures all systems are updated with the latest security patches within defined SLAs.

6.4. Cloud Security Posture Management (CSPM)

For cloud-native infrastructure, CSPM tools are utilized for continuous monitoring of security configurations, compliance, and threat detection.

7. Application Security (ALFRED AI and Platform)

7.1. Secure by Design and Secure Development Lifecycle (SDLC)

Security is architected into every phase of Our software development lifecycle, from threat modeling and secure coding practices to automated security testing and deployment.

7.2. Automated Code Review and Advanced Testing

All code undergoes rigorous automated (SAST, DAST, IAST) and manual security reviews and penetration testing to identify and remediate vulnerabilities before deployment.

7.3. API Security Gateway

Our APIs are protected by an advanced API Security Gateway, enforcing granular authentication (e.g., OAuth 2.0, mTLS), authorization, rate-limiting, and threat protection mechanisms.

7.4. AI Security Governance (ALFRED AI)

  • Prompt Injection Protection: Robust controls are implemented to prevent prompt injection attacks and ensure ALFRED AI operates within defined parameters.
  • Model Integrity: Continuous monitoring and validation of ALFRED AI models to prevent data poisoning, model drift, and unauthorized manipulation.
  • Secure Data Handling: Strict protocols for data used in AI training and inference, ensuring privacy and confidentiality.
  • Voice Pipeline: Real-time voice sessions are carried over encrypted transport via our voice infrastructure provider (LiveKit), which receives only the data needed to serve the session.
  • On-Device Wake Word: The optional "Hey Alfred" wake word runs entirely on your device (Picovoice Porcupine). No audio is recorded, stored, or transmitted until the wake word activates the concierge, and the feature can be disabled at any time.
  • Insight Grounding: Where ALFRED Insights calls large-language-model and web-search providers, only the query context required to produce the briefing is sent.

7.5. Mobile Application Security

  • Least-Privilege Permissions: The app requests only the device permissions a feature actually needs (microphone, camera and photo library, location, calendar, biometrics, SMS one-time codes, notifications), each optional and revocable at any time in your OS settings.
  • Diagnostics Hygiene: Screenshots are intentionally disabled in our crash and performance diagnostics to reduce the risk of exposing personal data.
  • Session Protection: Sensitive screens are shielded in the app switcher, and the app can be locked behind device biometrics.

7.6. Connected-Account Authorization Security

  • No Password Exposure: Optional Gmail and Google Calendar connections are authorized through Google's standard OAuth consent screen. We never see or store your Google password.
  • Server-Side Brokerage: Authorization is brokered by our backend (directly with Google or via our integration provider, Nylas); tokens are scoped to the access you grant and held server-side.
  • Revocable and Erasable: You can disconnect at any time, which revokes the grant upstream, and you can permanently erase everything the concierge has learned. Use of Google user data follows the Google API Services User Data Policy, including its Limited Use requirements.

7.7. Electronic Signature Integrity

Where a booking requires a signed agreement, signature requests, the resulting signed documents, and their audit metadata are processed through our e-signature workflow and retained as required for the contract and by law.

8. Incident Response, Business Continuity, and Disaster Recovery

8.1. Cyber Incident Response Plan (CIRP)

A comprehensive, Board-approved Cyber Incident Response Plan (CIRP) is in place, covering detection, analysis, containment, eradication, recovery, and post-incident review. The CIRP is regularly tested through tabletop exercises and live simulations.

8.2. Business Continuity (BC) and Disaster Recovery (DR)

Robust BC and DR plans are maintained and tested regularly to ensure the continuous availability and resilience of the Service. Critical data is backed up to geographically dispersed, encrypted, and immutable storage.

9. Third-Party Security Management and Supply Chain Risk

9.1. Rigorous Vendor Due Diligence

All third-party service providers undergo an exhaustive security due diligence process, including security questionnaires, audits, and certifications (e.g., SOC 2 Type II, ISO 27001). The Service currently relies on, among others: Stripe (card payments), Wirex (cryptocurrency payments), Sumsub (KYC/AML identity and biometric verification), LiveKit (real-time voice), Nylas (connected-account authorization), Google Firebase (authentication, cloud messaging, analytics, crash reporting, Firestore), and Sentry (error, performance and session diagnostics). Each receives only the data required for its function, under contract.

9.2. Contractual Security Requirements

Contracts with third parties include stringent security clauses, Data Protection Agreements (DPAs), and Service Level Agreements (SLAs) that mandate adherence to VAULTFY.AI's security standards and regulatory obligations.

9.3. Continuous Monitoring of Third-Party Risk

Third-party security posture is continuously monitored, and regular reviews are conducted to ensure ongoing compliance and risk mitigation.

10. Compliance, Audit, and Regulatory Engagement

10.1. Multi-Jurisdictional Regulatory Compliance

VAULTFY.AI maintains unwavering compliance with all relevant regulations, including UK GDPR, FCA guidelines, and continuously monitors the evolving regulatory landscape for FinTech, digital assets, and travel.

10.2. Independent Third-Party Audits and Certifications

Independent third-party audits (e.g., SOC 2 Type II, ISO 27001) are conducted periodically to assess the effectiveness of Our ISMS and ensure compliance with this Policy and external standards.

10.3. Proactive Regulatory Engagement

We maintain proactive engagement with regulatory bodies to ensure Our security practices remain at the forefront of compliance and best practice.

11. Policy Review and Continuous Improvement

This Security Policy will be reviewed at least annually, or more frequently as required by changes in technology, business operations, regulatory requirements, or the threat landscape. Our ISMS is subject to continuous improvement based on internal and external audit findings, risk assessments, and emerging threats.

12. Contact Information and CISO

For any questions regarding this Security Policy or to report a security incident, please contact Our Chief Information Security Officer at:

VAULTFY AI TRADING CO LTD

71-75 Shelton Street, Covent Garden

London, United Kingdom, WC2H 9JQ

Company No.: 17156633

Email: support@vaultfy.ai

[End of Security Policy (Fortress Edition)]

© 2026 Vaultfy. All rights reserved.
Services AI Concierge Privacy Policy Terms of Service Cookie Policy Disclosures Security Policy