← Back to Home

Cybersecurity Policy

Data King LLC — Effective April 28, 2026 · Version 1.0

1. Purpose and Scope

This Cybersecurity Policy establishes the security controls, standards, and responsibilities for Data King LLC and its Chatter AI platform. It applies to all systems, personnel, and third-party vendors involved in the development, operation, and maintenance of the Chatter AI application.

2. Data Classification and Handling

TierClassificationExamples
Tier 1ConfidentialBrokerage API keys, JWT signing secrets, database credentials
Tier 2SensitiveUser PII (email, name), trade history, billing records
Tier 3InternalApplication logs, performance metrics
Tier 4PublicTerms of Use, Privacy Policy, marketing content

Tier 1 data is stored exclusively in Google Cloud Secret Manager, never logged, and never transmitted in plain text. Tier 2 data is stored in Google Cloud SQL with AES-256 encryption at rest and transmitted only over TLS 1.2+.

3. Access Control and Privileged Access Management

All end-user access requires JWT authentication. Passwords are hashed with bcrypt; plaintext passwords are never stored. Google Cloud Console access is restricted to the Founder with 2FA enforced. All production infrastructure runs under least-privilege IAM service accounts. The database has no public IP — accessible only via private VPC from Cloud Run services.

4. Encryption of Data at Rest and in Transit

5. Vulnerability Management and Patch Management

Dependencies are audited via npm audit before each production deployment. Critical/high CVEs are remediated within 7 days. The platform runs on Google Cloud Run (serverless), so the underlying OS and runtime are automatically patched by Google. Container images are scanned via Google Cloud Artifact Analysis.

6. Incident Response and Disaster Recovery

SeverityDescriptionResponse Time
CriticalData breach, unauthorized account access< 1 hour
HighFull service outage, suspected intrusion< 4 hours
MediumPartial degradation, auth anomalies< 24 hours
LowPerformance issues, non-security bugs< 72 hours

RTO: 4 hours. RPO: 24 hours. Database automated daily backups with 7-day retention. Cloud Run services redeploy from Artifact Registry in under 10 minutes. Affected users notified within 72 hours of confirmed breach.

7. Physical Security

Chatter AI operates exclusively on Google Cloud Platform. No physical servers or data centers are maintained by Data King LLC. Google's data centers hold ISO 27001, SOC 2 Type II, and FedRAMP certifications. Developer workstations use full-disk encryption and 2FA for all cloud access.

8. Vendor Risk Management

VendorServiceCertifications
Google LLCCloud Run, Cloud SQL, Secret ManagerISO 27001, SOC 2 Type II, FedRAMP
Alpaca Securities LLCBrokerage APIFINRA, SIPC
Stripe Inc.Payment processingPCI DSS Level 1, SOC 2
Apple / GoogleApp distribution, IAPISO 27001

No third-party vendors are granted direct database access. All integrations are API-based with scoped credentials stored in Secret Manager.

9. Policy Review

Reviewed annually or following a significant security incident. Policy Owner: Carl D Hays III, Founder — carl@data-king.ai. Next Review: April 28, 2027.