Security

Last updated: August 18, 2026

Core controls

  • Cloudflare TLS, CDN, WAF-compatible controls, Turnstile-ready forms, and scoped runtime bindings.
  • Secrets stored as Cloudflare secrets or local development variables, never in source control.
  • Applicant documents remain unavailable until private R2 storage is enabled with public-development URLs disabled.
  • Encryption of Plaid access tokens before D1 storage and no storage of bank passwords.
  • Token-protected administrative APIs, audit events, prepared D1 statements, file-size and signature checks, and quarantine status.
  • PII excluded from commits, ordinary logs, screenshots, public AI tools, and model-ready datasets.

Responsible disclosure

Report a suspected vulnerability to security@stelopartners.com with reproduction steps and affected URLs. Do not access, alter, download, or retain another person's data; disrupt service; use social engineering; or publicly disclose an unresolved issue. Stelo does not currently promise a bug-bounty payment.

Incidents

Suspected incidents are contained, investigated, documented, and evaluated for contractual and legal notice obligations. Security controls reduce risk but cannot guarantee absolute security.