Security
Control what is collected, keep what is kept traceable, and never assume the perimeter holds. This page describes how that applies here and to the systems we operate.
How we think about it
Validity Financial builds and operates financial systems for other organizations. The standard we hold this site to is lower in complexity than the systems we deliver, but it is held to the same principle: control what is collected, keep what is kept traceable, and never assume the perimeter holds.
This website
The site is a static build served over HTTPS. It has no login, no user accounts, and no database of visitors. The only data path is the briefing form, which delivers your enquiry to us.
Client systems
Systems we design and operate for clients are engineered with controls established before launch rather than added afterwards. Depending on the engagement, that includes:
- Role-based access management
- Tiered approval workflows
- Transaction limits and thresholds
- Complete audit logs and event trails for every action
- Immutable transaction history
- Real-time monitoring and incident response workflows
- Failover and recovery procedures
Reporting a vulnerability
If you believe you have found a security issue affecting this site or a system we operate, tell us before you tell anyone else. Write to the address below with enough detail to reproduce the issue. We will acknowledge the report and keep you informed while we investigate.
We will not pursue action against anyone who reports an issue in good faith, avoids privacy violations and service degradation, and gives us reasonable time to respond.
Scope of this page
This page describes our approach. It is not a certification, an audit report, or a contractual commitment. Specific security obligations for an engagement are set out in the agreement for that engagement.
Write to adam@validity.financial or call 573-259-8978.