Skip to main content

Trust · security

Security overview

Last updated: 2026-05-31. What we do to keep your financial data safe, in plain English.

The short version

Authentication

Clerk handles passwords (bcrypt + salts), session management (HTTP-only secure cookies, rotated on privilege change), optional MFA (TOTP / passkeys), and credential-stuffing defense. We never see your password.

Transport security

Hosting + data layer

The Guardian — the AI security promise

Wealth's Guardian specialist exists specifically to refuse and rewrite outputs that overstep into advice. Concretely:

  1. The trinity backend produces an Analyst observation + Planner path, then the Guardian audits both before they are surfaced.
  2. Outputs that read as instructions ("buy this", "sell now", "open this account") are rewritten as questions or routed to a human-professional referral.
  3. When the Guardian abstains, the dashboard shows a "degraded — Guardian abstained" notice rather than silently falling back. Honest about limits.

What we monitor

If something goes wrong

Email security@cosmos369.ai for any security finding. We read every message within one business day and do not threaten or sue responsible disclosure researchers.

If we ever discover a breach affecting your account, we will notify you by email within 72 hours with what happened, what we are doing, and what you should do.

What we will not do


See also: Privacy · Terms · Back to Wealth