Wealt implements multiple layers of security to protect your personal and financial data:
Encryption
In transit: All data transmitted between your device and Wealt's servers is encrypted using TLS 1.3
At rest: Data stored in our databases and document storage is encrypted using AES-256
Documents: Files in your Vault are stored in AWS S3 with server-side encryption
Authentication security
Passwords are hashed using bcrypt (never stored in plain text)
Two-factor authentication (2FA) available for additional protection
Session tokens are rotated regularly
Automatic session expiry after periods of inactivityInfrastructure
Hosted on AWS with industry-standard security configurations
Regular security audits and penetration testing. Access controls limit which employees can access what data
All access is logged and monitored
KYC data
Identity documents are processed by trusted identity verification partners (SOC 2 certified, GDPR compliant)
Wealt only receives verification status, not raw document images.
Your responsibilities
Use a strong, unique passcode
Enable two-factor authentication
Don't share your login credentials
Log out from shared devices
