Advisory API Systems LLC

Security Practices Documentation

Effective Date: Upon First API Use
Version: 1.4
Last Updated: April 2026


1. INTRODUCTION

1.1 Purpose

This Security Practices Documentation describes the technical and organizational security measures implemented by Advisory API Systems LLC (“Company”) to protect the Portfolio Optimization API and the data processed through it.

1.2 Commitment to Security

Advisory API Systems is committed to maintaining the confidentiality, integrity, and availability of customer data. We implement security measures commensurate with the sensitivity of data processed and industry best practices.

1.3 Scope

This documentation covers security practices applicable to:


2. ORGANIZATIONAL SECURITY

2.1 Security Governance

Security Responsibility:
The Chief Compliance Officer serves as the security officer responsible for information security policy, implementation, and oversight.

Security Reviews:
Security practices are reviewed at least annually and updated as needed based on:

2.2 Personnel Security

Background Checks:
Personnel with access to production systems and customer data undergo background verification.

Confidentiality Agreements:
All personnel sign confidentiality agreements as a condition of engagement.

Security Training:
Personnel receive security awareness training covering:

Access Termination:
Access privileges are revoked immediately upon personnel termination or role change.

2.3 Vendor Management

Third-party vendors with access to customer data or systems are:


3. INFRASTRUCTURE SECURITY

3.1 Hosting Environment

Cloud Infrastructure:
The API is hosted on enterprise-grade cloud infrastructure located in Germany (European Union), benefiting from the strict data protection requirements of the EU General Data Protection Regulation (GDPR). Infrastructure features include:

Network Security:

3.2 System Hardening

Server Configuration:

Operating Systems:

3.3 Availability and Resilience

Redundancy:

Backup and Recovery:


4. APPLICATION SECURITY

4.1 Secure Development

Development Practices:

Vulnerability Management:

4.2 API Security

Authentication:

Authorization:

Input Validation:

4.3 Code Security

Dependencies:

Static Analysis:


5. DATA SECURITY

5.1 Data Classification

Data processed by the API is classified as:

Classification Description Handling Requirements
Confidential User financial data, PII Encryption, access controls
Internal API configurations, system data Access controls, change management
Public API documentation No restrictions

5.2 Encryption

Data in Transit:

Data at Rest:

5.3 Data Handling

Data Storage:
User data submitted via API requests is processed and retained after responses are delivered, including:

Data Minimization:

5.4 Credential and Key Management

Customer Access Tokens:

Third-Party Service Credentials (Payment Processor, Market Data, Address/VIN Validation, etc.):

Internal Encryption Keys:


6. ACCESS CONTROL

6.1 Authentication

Administrative Access:

User Access:

6.2 Authorization

Principle of Least Privilege:

Segregation of Duties:

6.3 Access Logging

Audit Trails:


7. NETWORK SECURITY

7.1 Perimeter Security

Firewalls:

DDoS Protection:

7.2 Secure Communications

API Endpoints:


8. MONITORING AND LOGGING

8.1 Security Monitoring

Continuous Monitoring:

Metrics Tracked:

8.2 Logging

Log Collection:

Log Contents:

8.3 Alerting

Alert Triggers:

Response Process:


9. INCIDENT RESPONSE

9.1 Incident Response Plan

Advisory API Systems maintains an incident response plan covering:

Preparation:

Detection and Analysis:

Containment and Eradication:

Recovery:

9.2 Incident Classification

Severity Description Response Time
Critical Data breach, complete service outage 1 hour
High Significant security event, major service degradation 4 hours
Medium Limited security event, minor service impact 1 business day
Low Potential vulnerability, no immediate impact 5 business days

9.3 User Notification

Users will be notified of security incidents affecting their data:


10. BUSINESS CONTINUITY

10.1 Disaster Recovery

Recovery Objectives:

Recovery Capabilities:

10.2 Backup Procedures

System Backups:


11. COMPLIANCE

11.1 Regulatory Framework

Advisory API Systems operates in compliance with applicable regulations:

Details regarding the Company’s privacy practices, including CCPA/CPRA disclosures, GLBA privacy notices, and GDPR compliance, are set forth in the Privacy Policy, which is incorporated by reference into the User Agreement.

11.2 Security Assessments

Internal Assessments:


12. CUSTOMER RESPONSIBILITIES

12.1 Shared Security Model

Security is a shared responsibility. Users are responsible for:

Access Token Protection:

Client-Side Security:

Incident Reporting:

12.2 Security Best Practices

Users should:


13. SECURITY QUESTIONNAIRE

The following addresses common security assessment questions:

13.1 Data Protection

Question Response
Is data encrypted in transit? Yes, TLS 1.2+ required
Is data encrypted at rest? Yes, AES-256
Where is data processed? Germany
How long is data retained? Term of Agreement; deleted upon written request subject to regulatory retention
Can customers delete their data? Yes, upon written (email) request at any time, subject to regulatory retention requirements

13.2 Access Control

Question Response
Is MFA required for administrative access? Yes
How is customer authentication handled? Bearer Access Token in X-User-Token header; 256-bit CSPRNG; SHA-256 hashed at rest
Is there role-based access control? Yes
Are access logs maintained? Yes

13.3 Infrastructure

Question Response
Is infrastructure hosted in certified data centers? Yes
Is there geographic redundancy? Yes
Are firewalls in place? Yes
Is there DDoS protection? Yes

13.4 Compliance

Question Response
Is there a security policy? Yes
Is there an incident response plan? Yes
Are security assessments conducted? Yes, annually
Is employee security training provided? Yes

14. CONTACT INFORMATION

Advisory API Systems LLC

Email: [email protected]
Phone: (310) 839-0358

Security Incident Reporting:
Email: [email protected]
Subject: SECURITY INCIDENT - [Brief Description]


This Security Practices Documentation is incorporated by reference into the User Agreement. By using the API, you acknowledge that you have reviewed this documentation.