Security
Security program overview
Eqivest is built around a Cloudflare-first architecture, explicit API contracts, and launch gates for identity, compliance, and payment workflows.
Platform boundaries
The public site, application, admin console, and API are separated. Privileged actions go through the Worker API, and frontend bundles do not contain privileged tokens.
Payment safety
Stripe owns payment collection for the MVP path. Eqivest records ledger state, compliance checks, and audit events rather than handling raw card details.
Operational controls
Launch controls can disable live investments until authorisation, investor checks, financial-promotion approval, and payment readiness are in place.
Report an issue
Security reports can be sent to security@eqivest.com.