Security
We take security seriously. Fortress Finance is built with institutional-grade security practices to protect your data and financial information.
All API keys and sensitive credentials are encrypted at rest using AES-256-GCM with unique keys per account.
Every Fortress account requires two-factor authentication via TOTP. No exceptions.
Exchange connections use read-only API permissions. Fortress can never move, trade, or withdraw your assets.
Every data query is scoped to the authenticated account, so users can only access their own data.
All API actions are logged with user ID, action type, timestamp, and IP address for compliance.
Hosted on Vercel with automatic HTTPS, DDoS protection, and edge network distribution.
We welcome security researchers to help us keep Fortress Finance safe. If you discover a security vulnerability, please report it responsibly.
Report the vulnerability
Email elijahhenry11@gmail.com (Fortress Finance support) with a detailed description, steps to reproduce, and impact assessment.
Wait for our response
We will acknowledge receipt within 48 hours and provide an estimated timeline for remediation.
Coordinated disclosure
Please do not disclose the vulnerability publicly until we have released a fix. We will credit you in our security advisory.
Security Contact
Contact: elijahhenry11@gmail.com (Fortress Finance support)