Security
Last updated: August 18, 2026
Core controls
- Cloudflare TLS, CDN, WAF-compatible controls, Turnstile-ready forms, and scoped runtime bindings.
- Secrets stored as Cloudflare secrets or local development variables, never in source control.
- Applicant documents remain unavailable until private R2 storage is enabled with public-development URLs disabled.
- Encryption of Plaid access tokens before D1 storage and no storage of bank passwords.
- Token-protected administrative APIs, audit events, prepared D1 statements, file-size and signature checks, and quarantine status.
- PII excluded from commits, ordinary logs, screenshots, public AI tools, and model-ready datasets.
Responsible disclosure
Report a suspected vulnerability to security@stelopartners.com with reproduction steps and affected URLs. Do not access, alter, download, or retain another person's data; disrupt service; use social engineering; or publicly disclose an unresolved issue. Stelo does not currently promise a bug-bounty payment.
Incidents
Suspected incidents are contained, investigated, documented, and evaluated for contractual and legal notice obligations. Security controls reduce risk but cannot guarantee absolute security.