SOC 2 Type II audited
Encrypted in transit and at rest
Never used to train AI models
SSO and MFA for every user
COMPLIANCE
We hold ourselves to the standards your
regulators expect.
Independent auditors test our controls. We build our program for firms that answer to regulators, and we document how every control works.
SOC 2 Type II
An independent auditor tests our controls for security, availability, and confidentiality over time, not at one point.
Encryption everywhere
TLS 1.2 or higher protects data in transit. AES-256 protects data at rest. Firms that need more control can hold their own keys.
Books & records
We keep complete, tamper-evident records that support your SEC and FINRA recordkeeping and exam duties.

TRUSTED DATA STORAGE
Your client data is the record of years of trust. We isolate it, keep it in the United States, and never use it to train AI models.
Firm-level isolation
We isolate each firm’s data at the tenant level. No firm can see the data, strategies, or philosophy of another firm.
US data residency
We store and process all customer data in US data centers. Your data does not leave the country.
No model training on your data
We run AI models in our own secure cloud environment. The model provider does not receive, store, or train on your prompts or outputs. WealthStream does not use your data to train or fine-tune any model.
FIDUCIARY-GRADE SECURITY
Built for firms that act in their clients’ best
interest.
Zero trust by design
No user or system gets trust by default. We verify, limit, and log every request for access.
Your approval comes first
Our engineers can access your data only with written approval from your firm, and only for a specific support request.
Independent testing
Third-party experts run penetration tests on the full platform twice each year. We assume a breach can occur, and we design our defenses for that.
Proven infrastructure
We build on enterprise cloud infrastructure with managed identity and AI services. The largest banks and asset managers trust the same infrastructure.
FULL OWNERSHIP
WealthStream supports standard single sign-on protocols, so your firm controls who gets access. You decide how long we keep data, who holds the keys, and who sees what.
Data retention
Set retention periods that match your policies and your regulatory duties.
Access visibility
Audit logs show who accessed which client record, and when. Your compliance team can export them for review.
Your own keys
Bring your own encryption keys through a managed key service. Revoke a key, and your data cannot be read.
SSO and MFA
Connect your identity provider through SAML 2.0 or OpenID Connect. Require multi-factor authentication for every user.
TRANSPARENT BY DESIGN
Every WealthStream recommendation shows its reasoning and its sources. The advisor makes the decision. Your compliance team can see why each recommendation appeared.

FAQ
Need our SOC 2 report, security questionnaire, or subprocessor list? Ask your WealthStream contact or visit the Trust Center.
How does WealthStream encrypt data?
We encrypt all data in transit with TLS 1.2 or higher. We encrypt all data at rest with AES-256. Firms that need more control can manage their own keys.
Who can see our client data?
Only the users your firm authorizes. WealthStream staff do not access your data without your written consent.
How do you make AI recommendations explainable?
Each recommendation links to the client facts, planning strategies, and firm philosophy that produced it. Advisors review the reasoning before they act. Nothing goes to a client without advisor approval.
What happens if there is a security incident?
We follow a tested incident response plan. We notify affected firms within 72 hours, so you can meet your own notice duties.
What happens to our data if we leave?
You can export all of your data first. When your contract ends, we permanently delete your data and all storage for your account, and we confirm this in writing.
See how WealthStream protects your firm, your advisors, and your clients.


