Security

Bank-grade security, by default.

You are trusting Osprey with EINs, SSNs, and your family's financial data. We protect it with field-level encryption, strong authentication, and complete audit logging — on every plan.

Field-level encryption

Sensitive identifiers like EINs and SSNs are encrypted with AES-256-GCM at the field level — not just at rest on disk. Even a database snapshot reveals nothing usable.

Two-factor authentication

TOTP-based 2FA adds a second layer beyond your password. New-device logins trigger an email alert so you always know when your account is accessed from somewhere new.

Encryption in transit

All traffic is served over TLS 1.2/1.3 with strong cipher suites and HSTS preloading. Documents are delivered through time-limited signed URLs, never exposed directly.

Tamper-evident audit logging

Every meaningful action is written to an append-only audit log with hash-chain integrity, so the record cannot be silently altered after the fact.

Resilient infrastructure

Hosted on U.S.-based servers with automated daily backups and a tested restore process, so your data survives hardware failure and human error alike.

Granular access control

Clients control exactly which accountants can see their data. Sessions are bound to context and rate-limited, and authentication endpoints carry the strictest throttling.

Trusted By Family Offices

Security you can point to

The controls that matter, stated plainly.

AES-256-GCM encryption TOTP 2FA TLS 1.2 / 1.3 Append-only audit logs Daily backups U.S.-based servers Signed-URL downloads

Questions about security?

We are happy to walk through our controls in detail.