Your Clients' Data,
Protected at Every Layer.
Built from the ground up to protect sensitive financial data. Your clients' trust demands nothing less.
The protections behind every piece of client data.
Six core safeguards — for how data lands in SurgeTK, how it's stored, and how it's accessed.
Encryption Everywhere
AES-256 at rest, TLS in transit. Every connection to SurgeTK is secured.
Enforced Two-Factor Auth
TOTP-based 2FA is required for every sign-in — not optional, and not skippable.
Private Cloud Storage
Client files live in private AWS S3 buckets, with access granted only through short-lived links.
Restricted Database Access
MongoDB Atlas with IP allowlisting and encrypted connections. Zero public exposure.
Vetted Infrastructure
Built on AWS, Heroku, and Stripe (PCI-DSS compliant). Only explicitly approved third-party scripts and origins are permitted to execute.
Continuous Monitoring
Audit trails, before/after snapshots, sign-in tracking, and real-time error tracking.
How We Protect Your Data
The implementation details behind every layer of protection.



Common Questions
What advisors ask us most about security.
Questions about security?
Our team is happy to walk through our security practices in detail.