Cyber Security Policy

Last Updated: July 1st, 2026


1. PURPOSE & SCOPE

This Information Security Policy (the "Policy") establishes how ABTrades, LLC, d/b/a Self Operating Brokerage (the "Company," "we," or "us") protects the confidentiality, integrity, and availability of the information and systems used to operate the Self Operating Brokerage platform (the "Service").

This Policy applies to:

All owners, employees, contractors, and third parties who access Company systems, data, or credentials ("Personnel").

All Company-owned and personally owned devices used to access Company systems ("Devices").

All data the Company creates, receives, stores, or transmits, including customer personal information, payment data, and brokerage integration credentials.

Compliance is mandatory for all Personnel. This Policy is reviewed at least annually and after any material change to the Service or a significant security incident.

Note on accuracy: This document is both an operating policy and a set of representations. Only publish, attest to, or share with third parties the controls the Company actually has in place. Overstating a control that is not implemented creates legal and regulatory exposure — particularly in a fintech context. Bracketed items must be confirmed or corrected before this Policy is finalized.


2. ROLES & RESPONSIBILITIES

Security Officer. Austin Bouley (founder & CEO) is accountable for this Policy, security decisions, incident response, and annual review. In a small team, this role may be held by the owner.

Personnel. Everyone with access is responsible for following this Policy, protecting credentials, using approved tools, and reporting suspected incidents immediately.

Third parties. Vendors and contractors must meet security expectations consistent with this Policy and are granted only the access necessary for their work.


3. DATA CLASSIFICATION

The Company handles the following categories of data, in order of sensitivity:

Class Examples Handling Restricted Brokerage API tokens/credentials, payment data, authentication secrets Encrypted at rest and in transit; access strictly limited; never stored in plaintext, logs, code, or chat Confidential Customer PII (name, email, phone), account/trade data, business records Encrypted in transit; access on a need-to-know basis Internal SOPs, internal docs, analytics Restricted to Personnel Public Marketing content, published policies No restriction

The Company does not take custody of, hold, withdraw, or transfer customer funds, and does not store customer brokerage login passwords. Brokerage connectivity is via scoped API authorization that the customer can revoke at any time (see Section 10).


4. ACCESS CONTROL & AUTHENTICATION

Least privilege. Personnel receive the minimum access needed for their role. Administrative and production access is limited to those who require it.

Multi-factor authentication (MFA). MFA is required on all accounts that access Company systems, source code, cloud infrastructure, email, payment tooling, and any system holding Restricted or Confidential data.

Unique accounts. Shared logins are prohibited wherever technically possible. Each person uses their own credentials.

Access reviews. Access is reviewed at least quarterly and whenever a role changes.

Offboarding. Access for departing Personnel is revoked within 12 hours, including email, code repositories, cloud consoles, password manager, and any production systems.


5. PASSWORD & CREDENTIAL MANAGEMENT

All Personnel use a Company-approved password manager (1Password) to generate and store strong, unique passwords.

Passwords are never reused across systems, shared over email/chat, or stored in plaintext.

Restricted secrets (API keys, tokens, database credentials) are stored in a secrets manager / encrypted vault — never hard-coded in source, committed to version control, or placed in documents or messages.

Suspected credential compromise must be reported immediately and the affected credential rotated without delay.


6. DEVICE & ENDPOINT SECURITY

All Devices used to access Company systems must have:

Full-disk encryption enabled.

A strong screen lock and automatic lock on inactivity.

Up-to-date operating system and software (security updates applied promptly).

Reputable anti-malware protection where applicable.

No use of untrusted public Wi-Fi for Restricted/Confidential work without a VPN.

Lost or stolen Devices with access to Company data must be reported immediately so access can be revoked and, where supported, the Device remotely wiped.


7. ENCRYPTION

In transit: All data transmitted between customers, the Service, and third parties (including brokerage APIs and payment processors) is encrypted using TLS 1.2 or higher.

At rest: Restricted and Confidential data is encrypted at rest, including databases, backups, and stored brokerage tokens.

Key/secret handling: Encryption keys and secrets are managed through secrets manager, with access restricted and logged.


8. APPLICATION & INFRASTRUCTURE SECURITY

Hosting. The Service runs on AWS through Laravel Cloud, which maintains its own physical and infrastructure security controls.

Secure development. Code changes go through review and testing before deployment to production. Secrets are never committed to source control.

Dependency management. Third-party libraries are kept reasonably current, and known-vulnerable dependencies are patched on a risk-prioritized basis.

Separation of environments. Development/testing environments are separated from production, and production customer data is not used in test environments without safeguards.

Least-privilege service accounts. Automated systems and integrations operate with the minimum permissions required.


9. LOGGING & MONITORING

The Company maintains logs of significant system and access events sufficient to investigate incidents.

Restricted data (tokens, secrets, full payment data) is excluded from logs.

Logs are protected against tampering and retained for 150 days.

Anomalies and alerts are reviewed and acted upon by the Security Officer.


10. BROKERAGE INTEGRATION SECURITY

Because the Service connects to customer brokerage accounts, the following controls apply specifically to integrations ("Integrations"):

Connections use scoped API authorization granted by the customer; the Company does not collect or store customer brokerage login passwords.

Integration tokens are treated as Restricted data: encrypted at rest, access-limited, and excluded from logs.

Customers may disconnect an Integration at any time, which revokes the Service's ongoing access.

The Company cannot move, withdraw, or take custody of customer funds through an Integration.

Integration limits (e.g., one authorized connection per brokerage) are enforced to reduce abuse and unauthorized access.


11. THIRD-PARTY / VENDOR RISK MANAGEMENT

The Company uses reputable third-party services to operate the Service, which may include SnapTrade (for broker integrations) and GoHighLevel (for CRM).

Before granting a vendor access to Restricted or Confidential data, the Company assesses the vendor's security posture at a level proportionate to the risk.

Payment card data is handled by a PCI-DSS-compliant processor (Stripe); the Company does not store full card numbers.

Vendors are granted least-privilege access and reviewed periodically.


12. INCIDENT RESPONSE

The Company maintains an incident response process to detect, contain, and remediate security incidents:

Report. Personnel report suspected incidents to the Security Officer immediately via email.

Assess & contain. The Security Officer assesses scope and severity and takes containment steps (e.g., rotating credentials, revoking access, isolating systems).

Remediate. Root cause is addressed and affected systems restored.

Notify. Where an incident involves unauthorized access to personal data, the Company notifies affected individuals and any authorities as required by applicable law, within legally required timeframes. Customers are advised to also alert their brokerage if they suspect account compromise.

Review. A post-incident review captures lessons learned and improvements.

Suspected trading malfunctions or unauthorized brokerage activity should also be reported per the Terms of Use, to [email protected].


13. BUSINESS CONTINUITY & BACKUPS

Critical data is backed up on a nightly basis, with backups encrypted and access-restricted.

Backup restoration is tested periodically to confirm recoverability.

The Company maintains a basic continuity plan to restore the Service after disruption (e.g., hosting outage, data loss).


14. ACCEPTABLE USE (PERSONNEL)

Personnel must:

Use Company systems and data only for legitimate business purposes.

Not share credentials, disable security controls, or circumvent this Policy.

Not install unauthorized software on Devices used for Company work where it introduces risk.

Not access, copy, or exfiltrate customer data except as required for their role.

Report phishing, suspicious activity, and security concerns promptly.

Violations may result in loss of access, termination of employment or contract, and legal action where warranted.


15. SECURITY AWARENESS

All Personnel receive security guidance appropriate to their role, including recognizing phishing and social engineering, safe credential handling, and this Policy's requirements. Awareness is refreshed at least annually.


16. PHYSICAL & REMOTE-WORK SECURITY

For a distributed/remote team, Personnel must keep Devices physically secure, avoid exposing screens with sensitive data in public, and not leave Devices unlocked or unattended in a way that risks unauthorized access.


17. CHANGE MANAGEMENT

Material changes to production systems follow a basic change process (review, test, deploy, ability to roll back) to reduce the risk of outages or security regressions.


18. INDEPENDENT AUDIT, POLICY ENFORCEMENT & REVIEW

The Company engages a qualified independent third party to conduct a security audit of the Service at least once per year, which includes a penetration test of the Service's production environment. Findings are reviewed by the Security Officer, and material issues are remediated on a risk-prioritized basis.

This Policy is reviewed at least annually and updated as the Service, team, and threat landscape evolve. Non-compliance is addressed by the Security Officer and may carry consequences up to termination and legal action.


19. CUSTOMER SECURITY COMMITMENTS (Trust Summary)

At Self Operating Brokerage, protecting your data is a priority:

We can't touch your money. We connect to your brokerage through scoped API access to automate the rules you set. We cannot withdraw, move, or take custody of your funds, and you can disconnect at any time.

We don't store your brokerage password. Connections use secure, revocable API authorization.

Encryption everywhere. Your data is encrypted in transit and at rest, including the credentials that link your brokerage.

Least-privilege access. Only authorized personnel can access systems holding your data, protected by multi-factor authentication.

Trusted payment handling. Payments are processed by a PCI-DSS-compliant provider; we do not store your full card number.

You're in control. You configure, edit, and pause your automations, and you retain full control of your brokerage account at all times.

Independently audited. Our security is reviewed by a qualified independent third party at least once a year.

No system is perfectly secure. We use commercially reasonable measures to protect your information, and we ask you to protect your account by using a strong, unique password and enabling multi-factor authentication. For details on how we handle personal data, see our Privacy Policy.

Questions about security? Contact [[email protected]].

Self Operating Brokerage

We help serious investors with $50K+ generate another stream of income using our Self Operating Brokerage system

Contact Details

  • (936) 442-1725

  • TN.US

Copyright 2026. Self Operating Brokerage. All rights reserved.