Security at Real Rate

We take the security of your financial data, portfolio tracking, and personal information seriously. Read on to understand our encryption standards and vulnerability disclosure policy.

How We Encrypt Your Data

No jargon, just plain English. Here is exactly how we protect your information from the moment it leaves your device to the moment it rests on our servers.

Data in Transit

When you send information to us (like logging in or adding to your portfolio), it travels through the internet. We use TLS 1.3 (Transport Layer Security), which essentially puts your data into an unbreakable, locked tunnel before it travels. Even if someone intercepts it, they will only see scrambled noise.

Data at Rest

When your data safely reaches our databases, we lock it away using AES-256 Encryption. This is the exact same standard used by banks and the military. Without the specific cryptographic keys—which are stored completely separately from the data—the information cannot be read by anyone, not even if the physical hard drives are stolen.

Strict Access Control

We operate on a strict Principle of Least Privilege. This means that no human at Real Rate can view your raw portfolio data unless absolutely necessary to provide you with support, and only with your explicit permission. We use robust hashing algorithms (like bcrypt) for your passwords—meaning we don't even know what your password is.


Responsible Disclosure Policy

If you spot a vulnerability, here is how to work with us.

At Real Rate, we deeply value the role of the independent security research community. If you believe you have discovered a vulnerability in our platform, we kindly ask that you report it to us immediately through our coordinated disclosure process.

Our Commitment to You

  • We will acknowledge receipt of your vulnerability report within 48 hours.
  • We will provide an estimated timeline for addressing the vulnerability.
  • We will not pursue legal action against researchers who follow this policy in good faith.
  • We will publicly acknowledge your contribution (if desired) once the issue is resolved.

The Rules of Engagement

To remain in compliance with our responsible disclosure policy, we require that you:

  • Do not exploit the vulnerability beyond what is strictly necessary to prove its existence (e.g., do not exfiltrate, delete, or modify user data).
  • Do not perform any Denial of Service (DoS/DDoS) attacks against our infrastructure.
  • Do not utilize social engineering, phishing, or physical attacks against Real Rate employees or offices.
  • Keep it confidential: Allow us adequate time to patch the vulnerability before making any details public.

How to Report

Please email all vulnerability reports directly to our security team at security@realrate.site. Include as much detail as possible: steps to reproduce, proofs of concept (PoC), and potential impact. If you have a CVSS score estimation, please include it.