Security
Built for firms that cannot afford to get security wrong.
Your clients trust you with their most sensitive financial information. WealthIris is designed from the ground up so that trust is never put at risk.
SOC 2 Type 2
Independently audited · Annual renewal
ISO 27001
Information security management
TLS 1.2+ / AES-256
Encryption at rest and in transit
How We Protect Your Data
Six commitments we make to every firm.
Your client data is never used to train AI
WealthIris does not use your firm’s data or your clients’ data to train, fine-tune, or improve any AI model. Your data answers your questions and nothing else.
Encrypted at rest and in transit
All data is encrypted using AES-256 at rest and TLS 1.2+ in transit. Credentials for your connected systems are stored in isolated, encrypted vaults, never in plain text.
Strict data isolation between firms
Every firm operates in a fully isolated environment. There is no shared data layer between clients. Your data cannot be accessed by, or commingled with any other firm.
Read-only connections to your systems
WealthIris connects to your portfolio and CRM systems in read-only mode. We query your data; we cannot write to it, modify records, or execute transactions on your behalf.
Complete audit trail on every query
Every query run through WealthIris is logged with a full audit trail, who asked, what was asked, and what data was returned. Available on demand for compliance reviews.
Role-based access controls
Administrators control who at the firm can access WealthIris and what they can see. User permissions are managed at the firm level and can be adjusted at any time.
INDEPENDENTLY VERIFIED
We hold SOC 2 Type 2 and ISO 27001 certification — both independently audited, every year.
Reports available to qualified firms under NDA.
Questions We Hear Most
Straight answers to the questions your CCO will ask.
Can anyone at WealthIris see our client data?
No. WealthIris employees do not have access to your client data in normal operations. Any access required for technical support requires your explicit authorization and is fully logged.
How are our platform credentials protected?
API credentials and access tokens for your connected systems are stored in encrypted, access-controlled vaults isolated from all other infrastructure. They are never logged or transmitted in plain text.
What happens if we offboard?
We understand compliance. When you off board, we give you a 30 day window to export your compliance logs. After that, we permanently and irrevocably erase them from our systems. All of your other data, is deleted immediately upon your subscription ending.
Are you compliant with SEC and FINRA data handling requirements?
WealthIris’s architecture is designed to support compliance with SEC Rule 17a-4 and FINRA 4370 obligations. Our audit trail and data handling practices are available for review by your CCO.
Has WealthIris undergone independent security review?
Yes. We hold SOC 2 Type 2 certification and ISO 27001 certification — both independently audited. Reports are available to qualified prospects under NDA.
Need our security documentation?
SOC 2 and ISO 27001 reports are available to qualified firms under NDA.