AskMyAdvisor® logoAskMyAdvisor®

AskMyAdvisor® Trust Center

AskMyAdvisor LLC operates the AskMyAdvisor® OS with a security first, compliance driven approach. We protect customer data using least privilege access, encryption in transit and at rest, and continuous monitoring. Security is an ongoing program, not a one time project. Additional details are available upon request for approved parties.

Controls

Password rules enforced
Source code access restricted and changes logged
Production access keys restricted and key management services
Access control procedures
Least-privilege access strictly enforced for produciton infrastructure
Data encrypted at rest
Secure disposal of electronic media containing sensitive data (PII, ePHI, etc.)
Customer data deleted after termination
Data Retention and Secure Deletion Policies
Documented security & privacy risk management process
Source code changes tested and approved
Outsourced development security requirements managed
Documented secure development and emergency change procedures
Secure connection means utilized
Web application firewalls configuration
Anti-malware monitoring
Intrusion detection tool
Infrastructure firewall
Centralized Log Collection and Monitoring
Automated system capacity and performance monitoring
Incident response procedures documented
Business continuity & disaster recovery plans documented and tested
Security incident logging and review
Business continuity plans ensure emergency functionality
Visitor sign-in, badging, and escort policy
Technology assets inventoried
Documented Vendor Management Program
Annual risk assessments performed
Confidentiality Agreement acknowledged by employees
Background checks performed on employees
Background checks performed on contractors
Security awareness training implemented
Whisteblower mechanism maintained
Multi-availability zones
Documentation available to internal and external users
Customer support channels available
Automatic Session Timeout Enforcement
Information security policies and procedures
Authorized Communication of Material System Changes
Confidentiality Agreement acknowledged by contractors
Patch management process developed

FAQs

AskMyAdvisor stores only the data necessary to operate the AskMyAdvisor® OS, including advisor and client-provided information. We do not sell customer data.

Access is restricted using role-based access controls and least-privilege principles. Administrative access is limited and monitored.

AskMyAdvisor maintains an incident response process to investigate, contain, and remediate security events. Impacted parties are notified as appropriate.