Security

Institutional security standards

Wolfrayet is built to institutional security standards. We protect user data, enforce access controls, and maintain immutable audit trails across all intelligence operations.

Encryption

All data in transit is encrypted via TLS 1.2+. Data at rest is encrypted using AES-256 within Supabase PostgreSQL. API keys and secrets are stored as environment variables and never exposed to the client.

Authentication

Enterprise authentication via Clerk with multi-factor support, session management, and JWT-based identity bridging to Supabase Row-Level Security policies.

Infrastructure

Deployed on Vercel with serverless functions and edge caching. Database hosted on Supabase with automated backups, connection pooling, and geographic redundancy.

Audit Logging

All intelligence events, model runs, and user actions are recorded in append-only audit logs. Events are immutable and queryable for compliance and governance review.

Model Governance

Models require approval workflows before deployment. Version history, experiment results, and governance decisions are permanently archived.

Event Immutability

Intelligence events and billing events are write-once records. Historical data cannot be retroactively modified, ensuring audit integrity.

Data Protection

Row-Level Security isolates user data by Clerk identity. Service role keys are server-only. No live brokerage connections. No real-money execution.

Responsible AI

Deterministic models drive recommendations. LLMs explain outputs but never serve as the primary decision engine. Full reasoning chains and evidence attribution are provided for every analytical output.

Wolfrayet provides investment intelligence, market research, analytics, and decision-support tools. Nothing on this platform constitutes investment advice, financial advice, tax advice, legal advice, or a recommendation to buy or sell securities. All investments involve risk, including possible loss of principal. Past performance does not guarantee future results. Users remain solely responsible for all investment decisions.