Chapter · VII

Security &
trust

Client data moves through custodial, CRM, and planning systems that are individually audited and jointly monitored. This is a maintained overview of the controls that keep prospect information private end-to-end.

Reviewed by SEIA Growth Labs. Not an independent certification.

Encryption in transit & at rest

All data exchanged between custodians, Salesforce, and PlanScout travels over TLS 1.2+ and is encrypted at rest with provider-managed AES-256.

Least-privilege access

BDO, PlanScout, and advisor teams see only the fields their stage requires. Role-based access is reviewed each quarter.

Custodial source of truth

Account and holdings data stays with Schwab and Fidelity. SEIA operates on read-only snapshots plus advisor-entered planning notes.

Audit trail on every stage

Each workflow stage writes an immutable event — actor, timestamp, action — used for SLA and compliance review.

Vendor due diligence

PlanScout and other sub-processors are reviewed annually for SOC 2 posture, breach history, and data-handling scope.

Incident response

A written playbook covers detection, containment, client notification windows, and post-mortem review across all systems in the flow.