Security

Protecting customer information

Last updated September 8, 2026

Security overview. This page summarizes WealthStream’s standard security practices. It is not a substitute for the confidentiality, privacy, security, incident-notification, audit, or service-level terms in a signed Customer Agreement or Data Protection Addendum. Those documents control.

WealthStream serves wealth management firms that handle highly sensitive client information. Our security program combines cloud, access, encryption, personnel, vendor, testing, resilience, and incident-response controls.

WealthStream is an AI-native advice-intelligence software provider for wealth management firms. WealthStream is not a bank, broker-dealer, registered investment adviser, custodian, or fiduciary. It does not hold customer cash or securities, execute trades, transfer funds, or communicate directly with an advisory firm’s End Clients.


Custody, account protection, and deposit insurance, where applicable, are provided by the financial institutions that hold the relevant accounts, not by the WealthStream software.

WealthStream maintains a written information-security program with administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Customer Data; address anticipated threats and hazards; and reduce the risk of unauthorized access, use, disclosure, alteration, or destruction. The program is periodically reviewed and updated to address changing risks.

Cloud resilience


Hosting on Amazon Web Services with geographic redundancy and commercially reasonable business-continuity and disaster-recovery practices.


Data separation


Firm-level logical isolation, access controls, encryption, and namespace separation in the standard multi-tenant environment.


Access control


Role-based access controls and logging of administrative access and material user actions.


Encryption


Encryption in transit using TLS 1.2 or higher and encryption at rest using AES-256.


Testing and monitoring


A vulnerability-management and penetration-testing program.


Personnel safeguards


Confidentiality obligations, role-appropriate background screening where permitted by law, and security-awareness training.

Customers retain ownership of Customer Data. WealthStream uses Customer Data only as permitted by the applicable Customer Agreement and does not use Customer Data, AI inputs, or AI outputs to train or fine-tune models for other customers without the customer’s prior written consent.


Under WealthStream’s standard contractual framework, AI processing of Customer Data is performed through managed model services operating within WealthStream’s cloud environment. Third-party model providers are contractually prohibited from using Customer Data to train or improve models, and Customer Data is not transmitted to, stored on, or retained by systems operated by those model providers.


Subprocessors are subject to contractual confidentiality and data-protection requirements. Customer Data is stored in the United States unless otherwise agreed in writing. A current list of model providers and subprocessors is available to customers upon written request.

WealthStream maintains backup, business-continuity, disaster-recovery, and incident-response processes. If a confirmed security incident affects Customer Data, WealthStream investigates, takes reasonable steps to contain and mitigate the incident, and notifies and cooperates with affected customers in accordance with the applicable Customer Agreement and law.


Specific notification periods, recovery objectives, customer audit rights, and other contractual commitments are set out in the applicable Customer Agreement, Data Protection Addendum, or statement of work.

WealthStream’s program includes vulnerability management, penetration testing, and an independent assessment using an industry-accepted control standard or framework. Available security and assurance documentation may be provided to customers under appropriate confidentiality protections and in accordance with the applicable Customer Agreement.


No security program can eliminate every risk. WealthStream may update its security measures, provided that any updates do not materially diminish the overall security of Customer Data or the Services as required by the applicable Customer Agreement.

Security is shared. Customers are responsible for managing Authorized Users, credentials, roles, permissions, connected-system authorizations, endpoint and network security, lawful data submission, and their own supervisory, privacy, compliance, and records-management obligations.


To report a suspected vulnerability or security concern, use WealthStream’s Contact page and identify the message as a security matter. Do not include client records, credentials, or other sensitive information in the initial report.

© 2026 WealthStream. All rights reserved.

© 2026 WealthStream. All rights reserved.

© 2026 WealthStream. All rights reserved.

© 2026 WealthStream. All rights reserved.