← Back

Security

Your financial data deserves the highest level of protection. Here's how we keep it safe.

🔐
AES-256
Encryption at rest
🔒
TLS 1.3
Encryption in transit
🛡️
SOC 2
Compliance roadmap

Encryption

At Rest — AES-256

All data stored in our databases and file storage is encrypted using AES-256, the same standard used by the U.S. government and leading financial institutions. Sensitive fields (SSNs, EINs, financial documents) receive additional field-level encryption.

In Transit — TLS 1.3

All communications between your browser and PrepSBA are encrypted using TLS 1.3, the latest transport security standard. Older TLS versions are rejected. We enforce HTTPS sitewide with HSTS headers.

Access Controls

  • Multi-factor authentication (MFA) enforced for all user and staff accounts
  • Role-based access control (RBAC) — employees access only what their role requires
  • All administrative actions are logged and auditable
  • Automated session expiration and suspicious activity alerts
  • Passwords stored using bcrypt hashing with per-user salts

Infrastructure & Data Handling

PrepSBA is hosted on SOC 2 Type II certified cloud infrastructure in the United States. We do not store your data outside of the US. Our infrastructure includes:

  • Isolated network environments with private subnets for sensitive data
  • Automated daily backups with encrypted off-site storage
  • DDoS protection and Web Application Firewall (WAF)
  • Continuous vulnerability scanning and dependency audits
  • Penetration testing conducted annually by independent security firms
  • Secrets management using industry-standard vault services — no hard-coded credentials

SOC 2 Readiness

PrepSBA is actively working toward SOC 2 Type II certification. Our security controls are designed around the five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. We expect to complete our Type II audit by Q4 2026. Learn more about our SOC 2 roadmap →

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a potential security issue in our platform, please report it to us responsibly before public disclosure. We are committed to working with the security community to protect our users.

Do not exploit vulnerabilities — do not access, modify, or delete user data during your research. Out-of-scope: physical attacks, social engineering, DDoS testing.

To report a vulnerability, email security@prepsba.com with a detailed description and reproduction steps. We will acknowledge reports within 24 hours and provide regular updates on remediation.

Security Questions?

For security concerns, vulnerability reports, or compliance questions, contact our security team.

security@prepsba.com