Security at TradeInsight.info (formerly PelosiTrade.com)

At TradeInsight.info we take your privacy and security very seriously. This page provides some general information about our practices to give you confidence in how we protect your information.

We are serious about protecting your data and privacy

Data Centre Security

  • TradeInsight.info hosts its infrastructure on various cloud providers including AWS, Cloudflare and Oracle Cloud,
  • We follow the best practices of the cloud providers, which allows us to take advantage of their secure, distributed, fault-tolerant environment.

Failover and Disaster Recovery

  • Our systems are designed and built with disaster recovery in mind.
  • Our infrastructure and data are distributed across multiple Cloud Availability Zones, and systems will continue to operate even if one of these data centres fails.

Encryption

  • The entire TradeInsight.info application is encrypted using TLS.
  • We proudly maintain an A rating from Qualys/SSL Labs.
  • Our data storage, including the database, uses encryption at rest and in transit.

Data loss protection

  • All our data is automatically backed up on a daily basis.

Protection is not just about data

Application level security

  • Login pages and logins via TradeInsight.info have brute force protection.
  • We store all passwords in hashed form so we can't see them.

Vulnerability Scanning

  • We use third party security tools to continuously scan for vulnerabilities as part of our continuous integration pipeline.

Internal IT security

  • Only authorised employees have access to our software version control, and they only have the lowest level of access they need to do their job.
  • Access to servers, source code and third party tools is secured with two-factor authentication wherever possible.

Payment Card Industry (PCI) commitments

  • When you purchase a paid subscription to TradeInsight.info, your credit card details are not transmitted through or stored on our systems. Instead, we rely on Stripe, a company dedicated to this task. Stripe is PCI Service Provider Level 1 certified and their security information is available online. You can read more about Stripe's security information at https://stripe.com/help/security.

Responsible disclosure

  • If you have discovered a vulnerability in the TradeInsight.info application, please don't hesitate to contact us at Contact Us. We investigate all security concerns brought to our attention and take a proactive approach to emerging security issues.