In short
- Only invited people can reach the app at all, and they then sign in to the app itself.
- dmscs never sees a password: sign-in goes through Google.
- The app sits on a private network with no open ports to the internet.
- Everything is encrypted in transit and at rest.
- Your data is never sold, shared for advertising, or used for anything but showing it to you.
Getting in: two separate checks
The front door. Before any request reaches the app, Cloudflare Access checks that you're signed in with Google and that your email is on the invite list. Anyone else is turned away at Cloudflare's edge and never touches the app.
The app's own sign-in. Inside, you sign in to dmscs with Google as well. The app checks that the person who came through the front door is the same person signing in, on every request, and refuses the request if they differ.
Both checks use your Google account, so its security matters most. Turn on Google's 2-Step Verification if you haven't already.
Where it runs
The app and its database run on Amazon Web Services in the United States. They live on a private network that accepts no connections from the internet: traffic arrives only through an outbound, encrypted tunnel to Cloudflare.
The app runs as an unprivileged user on a read-only file system, and its software dependencies are pinned and checked for known vulnerabilities on every change.
Encryption
- In transit: every connection, from your browser to Cloudflare and from Cloudflare to the app, is encrypted.
- At rest: the database and its backups are encrypted with a dedicated key.
- Linked accounts: when account linking arrives, the tokens that let dmscs read a linked account will be encrypted separately from the rest of the database. Your bank or brokerage password goes to the linking service, Plaid, and never to dmscs.
Kept separate
Each person's positions, accounts and settings belong to their account, and every request is limited to the signed-in person's own data. One person can't see another's portfolio.
The person who runs dmscs has administrative access to the database to keep it running, and doesn't look at anyone's data except to fix a problem they've reported or when the law requires it. The privacy policy has the details.
What leaves the app
To look up prices and fund contents, dmscs sends ticker symbols and security identifiers to market data sources. Those requests never include your name, email, amounts or accounts. Company logos are fetched by the company's website address.
There are no advertising or analytics trackers in the app or on this site.
Watching for trouble
The cloud account runs automated threat detection, and security findings are sent straight to the operator by email. Changes to the infrastructure are reviewed and applied by hand, and the app is deployed only from its main line of code, through a recorded process.
What you can do
- Use 2-Step Verification on your Google account.
- Sign out when you're done on a shared or borrowed computer.
- Don't forward your invite: it's tied to the email it was sent to.
- If something looks wrong, say so (below).
Reporting a problem
If you think you've found a security issue, or something in your account looks wrong, email [email protected]. Please include what you saw and when. Reports are read by a person and answered.