SurgeTK
Security & Trust

Your Clients' Data,
Protected at Every Layer.

Built from the ground up to protect sensitive financial data. Your clients' trust demands nothing less.

Encryption
AES-256 · TLS
Sign-in
2FA enforced
Storage
Private AWS S3
Monitoring
24/7 audit trail
Security

The protections behind every piece of client data.

Six core safeguards — for how data lands in SurgeTK, how it's stored, and how it's accessed.

Encryption Everywhere

AES-256 at rest, TLS in transit. Every connection to SurgeTK is secured.

Enforced Two-Factor Auth

TOTP-based 2FA is required for every sign-in — not optional, and not skippable.

Private Cloud Storage

Client files live in private AWS S3 buckets, with access granted only through short-lived links.

Restricted Database Access

MongoDB Atlas with IP allowlisting and encrypted connections. Zero public exposure.

Vetted Infrastructure

Built on AWS, Heroku, and Stripe (PCI-DSS compliant). Only explicitly approved third-party scripts and origins are permitted to execute.

Continuous Monitoring

Audit trails, before/after snapshots, sign-in tracking, and real-time error tracking.

SOC 2 (in progress)GDPRCCPAPCI-DSS via Stripe
Full security report

How We Protect Your Data

The implementation details behind every layer of protection.

Built on the same infrastructure trusted by banks & Fortune 500s
SOC 2 in progress · Last security review · 04/2026
Encryption
AES-256
At rest, with TLS in transit
2FA
Required
For every account
File links
Short-lived
Signed URLs auto-revoke
Monitored collections
9
Continuous data integrity checks
Powered by
5 enterprise vendors
AWS
AWS
MongoDB
MongoDB
Stripe
Stripe
Heroku
Heroku
Sentry
Sentry

Common Questions

What advisors ask us most about security.

Questions about security?

Our team is happy to walk through our security practices in detail.