← Mobius Ledger

Information Security Policy

Mobius Digital LLC · Version 1.0 · Effective 6 September 2026 · Reviewed annually, next review September 2027

Scope. This policy covers every system Mobius Digital LLC operates that stores or processes company financial data, client advertising data, or credentials — including Mobius Ledger and the internal tools hosted at tools.go-mobius-digital.com. It applies to all personnel and contractors with access to those systems.

Owner. Cole Wetzler, Owner, is responsible for information security and for reviewing this policy annually. Contact: cole@go-mobius-digital.com.

1. Risk identification and review

The owner maintains a written inventory of systems that hold sensitive data, the categories of data in each, and the third parties that process data on our behalf. That inventory is reviewed at least annually and whenever a new integration is added. Adding any integration that reads financial or client data requires a documented decision on what data it needs, the minimum permissions to achieve it, and where its credentials will be stored.

Current sensitive systems: Cloudflare (application hosting, D1 databases, KV storage, secrets), Google Workspace (identity, mail, documents), Plaid (bank connectivity), Stripe (payment processing), Slack (internal messaging), Anthropic API (receipt and report text processing), Meta and Google advertising platforms (client campaign data).

2. Access control

3. Encryption

4. Vulnerability and patch management

Production runs entirely on managed serverless infrastructure (Cloudflare Workers, D1, KV). We operate no servers, virtual machines, or containers, so operating-system and runtime patching for production is performed by the platform provider on a continuous basis. Our practices for the surface we do control:

5. Data retention and deletion

We keep only what we need, for only as long as we need it. This schedule is reviewed annually alongside this policy.

DataRetentionThen
Company financial transactions and receipts7 years from the end of the relevant tax yearDeleted
Plaid and Stripe access tokensLife of the connectionRevoked at the provider and deleted on disconnection
Client advertising performance dataLife of the engagement plus 12 monthsDeleted
Application logs30 daysExpire automatically

Disconnecting a financial account stops collection immediately and removes the stored access token. Transactions already imported are retained for the period above because they form our own accounting records. Deletion requests relating to data we hold are handled by the owner and actioned within 30 days.

6. Third parties

Before a third party is given access to sensitive data we confirm it is an established provider with a published security posture and a data processing agreement, and we grant it the narrowest scope that meets the need. We do not sell, rent, license, or otherwise share company or client data with third parties for their own purposes.

7. Incident response

  1. Contain. On suspicion of a compromise, revoke or rotate the affected credentials and disable the affected integration immediately.
  2. Assess. Determine what data was reachable, over what period, and by whom, using platform audit logs.
  3. Notify. Inform affected parties, and any provider whose data or credentials were involved — including Plaid, where its data or credentials are implicated — without undue delay and within any period their agreements require. Regulators and clients are notified where the applicable law or contract requires it.
  4. Remediate and record. Fix the root cause, write down what happened and what changed, and revisit this policy if the incident exposes a gap.

Suspected incidents are reported to cole@go-mobius-digital.com.

8. Review

This policy is reviewed at least annually by the owner, and whenever a significant new system or integration is introduced. The version and effective date at the top of this page record the current revision.