Security & Compliance Portal

Application: WTD

Information Security Policy (ISP)

The core framework defining WTD's overall security governance and infrastructure protection.

Active

Access Control Policy

Formal documentation of role-based permissions and the principle of least privilege.

Active

Vulnerability Management

Our 14-day patching SLA and formal process for identifying and reporting security risks.

Active

Secure Authentication Attestation

Attesting to the use of Yubikeys, TOTP MFA, and encrypted credential storage.

Active

Access Review & Audit Policy

Documentation of periodic audits triggered by user changes or software updates.

Active

Consumer MFA Implementation

Requirement for all users to pass MFA before accessing the Plaid Link interface.

Active

Access De-provisioning

Automated procedures for the immediate revocation of access for removed users.

Active

Privacy Policy

Public statement on data collection minimalism and commitment to user privacy.

Active

Data Deletion & Retention

Outlining the 2-month retention lifecycle for backups and active application data.

Active