PT Biz

Information Security Policy

Information Security Policy

PT Biz — Operational Information Security Program

Version 1.0
Last Updated: September 26, 2026
Active & Operationalized

Policy Statement

PT Biz has a documented information security policy, supporting procedures, and an operational information security program that is continuously matured. Our program is designed to identify, mitigate, and monitor information security risks relevant to our business and the data entrusted to us by our clients.

1. Purpose & Scope

This Information Security Policy establishes the framework by which PT Biz ("the Company") identifies, assesses, mitigates, and monitors information security risks. It applies to all systems, applications, data, and personnel (employees, contractors, and third-party service providers) that access, process, store, or transmit Company or client data.

2. Information Security Program

The Company maintains an operational information security program that includes the following components:

  • A documented set of security policies and procedures reviewed at least annually.
  • Risk assessments conducted periodically to identify and prioritize threats to confidentiality, integrity, and availability of data.
  • Remediation plans and controls implemented to mitigate identified risks.
  • Continuous monitoring processes to detect and respond to security incidents in a timely manner.
  • Employee awareness and training on data security responsibilities.

3. Risk Identification

The Company employs the following practices to identify information security risks:

  • Regular review of system access logs and authentication events.
  • Evaluation of third-party vendors and service providers for security compliance prior to integration.
  • Monitoring of industry threat intelligence sources for emerging vulnerabilities.
  • Periodic internal reviews of data flows, access controls, and system configurations.

4. Risk Mitigation & Controls

Controls implemented to mitigate identified risks include:

  • Access Control: Role-based access controls (RBAC) are enforced. Access is granted on a least-privilege basis and reviewed regularly.
  • Encryption: Data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256, the industry-standard algorithm. All consumer financial data received from the Plaid API is stored exclusively on our SOC 2 Type II certified cloud infrastructure, which enforces AES-256 encryption at rest by default for all stored data.
  • Authentication: Multi-factor authentication (MFA) is required for administrative access to production systems.
  • Secure Development: The application is built on a managed cloud platform with built-in security controls, automatic patching, and infrastructure hardening.
  • Vendor Management: Third-party integrations (e.g., Stripe for payments, Plaid for financial data) are evaluated for SOC 2 compliance and adhere to their respective security standards.
  • Data Minimization: Only the minimum necessary client data is collected and retained to provide the service.

5. Monitoring & Incident Response

The Company maintains ongoing monitoring and incident response capabilities:

  • System logs and error tracking are monitored continuously for anomalous activity.
  • Security incidents are documented, investigated, and remediated according to a defined incident response procedure.
  • Affected parties are notified of data breaches in accordance with applicable laws and regulations within required timeframes.
  • Post-incident reviews are conducted to improve controls and prevent recurrence.

6. Data Privacy & Client Data Protection

The Company is committed to protecting client data:

  • Client personal and financial data is never sold or shared with unauthorized third parties.
  • Financial account data accessed via Plaid is used solely for the purpose of transaction syncing and expense tracking within the application.
  • Clients retain the right to request deletion of their data at any time.
  • Data retention is limited to the period necessary to provide the service or as required by law.

7. Infrastructure & Cloud Security

  • The application is hosted on a SOC 2 Type II certified cloud infrastructure provider.
  • Infrastructure is maintained with automatic security updates and patch management.
  • Production and development environments are logically separated.
  • Backups are performed regularly and tested for recoverability.

8. Development & Vulnerability Management

PT Biz addresses vulnerability management through a fully managed cloud infrastructure model:

  • Managed Infrastructure: The application runs entirely on a managed cloud platform (Base44) that handles infrastructure provisioning, security patching, and hardening automatically. There are no self-managed server instances requiring manual vulnerability scanning.
  • Automatic Patching: The underlying platform applies security patches and dependency updates automatically, ensuring production assets are continuously up-to-date without manual intervention.
  • No Employee Laptop Fleet: PT Biz is operated by a sole operator with no employee or contractor laptop fleet requiring endpoint vulnerability scanning programs.
  • EOL Software Monitoring: Application dependencies are monitored for end-of-life (EOL) status. Outdated or deprecated packages are updated as part of routine development practices.
  • Third-Party Security Inheritance: Security controls, vulnerability scanning, and patch management for production infrastructure are inherited from the SOC 2 Type II certified cloud provider, whose audit reports are available upon request.

9. Policy Review & Continuous Improvement

This policy and supporting procedures are:

  • Reviewed and updated at least annually, or following any significant security incident or material change to the business.
  • Communicated to all relevant personnel and made publicly available.
  • Matured continuously as the threat landscape evolves and the business grows.

PT Biz

Questions about this policy? Contact us at support@ptbiz.app

Effective Date: September 26, 2026 · Version 1.0