Security Policy
Smart Algos Capital · Smart Algos Investment Solution Ltd (Kenya) · Last updated: July 30, 2026
Our commitment
Smart Algos Investment Solution Ltd takes the security of your data, subscriptions, and payments seriously. We apply industry-standard security practices across our infrastructure and maintain transparency about what protections are in place.
1. Compliance Standards
Our platform and infrastructure are designed to meet or align with the following standards:
2. Data Encryption
- All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS)
- Data stored in our database is encrypted at rest using AES-256
- Passwords and authentication tokens are never stored in plain text — bcrypt hashing with salt is used
- Sensitive environment variables (API keys, payment credentials) are stored in encrypted secret vaults and never committed to source code
3. Infrastructure Security
Smart Algos Capital is hosted on enterprise-grade cloud infrastructure:
- Vercel — globally distributed edge hosting with DDoS protection and automated HTTPS
- Supabase — SOC 2 Type II certified database and authentication platform with row-level security (RLS) policies ensuring users can only access their own data
- Firewall rules and rate limiting are applied to all authentication and payment endpoints to prevent brute-force attacks
- Automated vulnerability scanning on every deployment detects known dependency weaknesses
- Database access is restricted to authorised services via private networking — no direct public database access is permitted
- Regular automated backups with point-in-time recovery capability
4. Payment Security
We do not handle, store, or transmit full payment card numbers, CVV codes, or other raw card data. All payment processing is handled end-to-end by Paystack, a PCI-DSS Level 1 certified payment processor.
- We only receive a transaction reference and payment status from Paystack
- Paystack's payment pages use extended validation (EV) SSL certificates
- Transactions are monitored in real time for fraud and suspicious patterns
- Chargebacks and payment disputes are handled through Paystack's secure portal
5. Access Controls
- All administrative access to production systems requires multi-factor authentication (MFA)
- Internal access to user data follows the principle of least privilege — team members only access what they need for their role
- All administrative actions on user data are logged and auditable
- Admin sessions are memory-only and do not persist after browser close — they require re-authentication each session
6. Security Monitoring
- Automated monitoring for unusual login attempts, high request rates, and anomalous access patterns
- Rate limiting on authentication, subscription, and payment endpoints
- Dependency vulnerability alerts through automated package scanning on every build
- Error monitoring and alerting for unexpected server-side failures that could indicate exploitation attempts
7. Incident Response
In the event of a confirmed security breach affecting user data, we commit to:
- Notifying affected users within 72 hours of discovery, where required by applicable law
- Providing clear information about what data was affected, what we are doing to contain the incident, and what steps users should take
- Cooperating with relevant authorities and regulators as required
- Conducting a post-incident review and implementing corrective measures to prevent recurrence
8. Your Responsibility
Security is a shared responsibility. To protect your account:
- Use a strong, unique password not reused across other services
- Never share your login credentials or subscription access with others
- Log out after using the platform on shared or public devices
- Keep your registered email account secure — it is the primary recovery mechanism
- Report any suspicious activity or suspected unauthorised access immediately
9. Responsible Disclosure
If you discover a security vulnerability in Smart Algos Capital, we encourage responsible disclosure — please report it to us privately before disclosing it publicly so we can address it promptly.
How to report: Email security@smartalgos.com with a description of the vulnerability, steps to reproduce, and the potential impact. We will acknowledge your report within 48 business hours.
We will not take legal action against researchers who report vulnerabilities in good faith and follow responsible disclosure practices.
10. Contact
Security reports: security@smartalgos.com
General support: support@smartalgos.com
Company: Smart Algos Investment Solution Ltd · Embu, Kenya