ComplianceData Security & Encryption

Data Security & Encryption

Sterling protects your client data using industry-standard security practices. This page explains how data is secured both during transmission and while stored in our systems.

Encryption in Transit

All data transmitted between your browser and Sterling's servers is encrypted using HTTPS with TLS (Transport Layer Security). This prevents anyone from intercepting or reading data as it travels over the internet.

  • All web traffic uses HTTPS encryption
  • Document uploads and downloads are encrypted
  • AI requests are transmitted over secure channels

Encryption at Rest

Client data stored in Sterling is protected by enterprise cloud providers with built-in encryption:

  • Database: MongoDB Atlas with encryption at rest enabled
  • Documents: AWS S3 with server-side encryption
  • Credentials: AWS Secrets Manager for secure key storage

Enterprise Infrastructure

Sterling runs on the same cloud infrastructure trusted by major financial institutions, healthcare organizations, and government agencies.


Authentication Security

Sterling uses Auth0, an enterprise identity platform, for user authentication. This provides:

  • Secure password storage with industry-standard hashing
  • Sessions expire after 12 hours, and after 1 hour of inactivity
  • Protection against common attacks (brute force, credential stuffing)

No Local Data Storage

Sterling does not store sensitive client data on your local device. All data remains on secure cloud servers. When you close your browser, no client information is left behind on your computer.


Infrastructure Provider Certifications

The cloud platforms Sterling is built on hold independent security certifications. These are the providers' certifications, covering the infrastructure Sterling runs on:

  • Amazon Web Services — SOC 2 Type II, ISO 27001, and GDPR commitments covering document storage, credential management, and AI processing
  • MongoDB — SOC 2 Type II and ISO 27001 covering the database platform
  • Auth0 (Okta) — SOC 2 Type II and ISO 27001 covering authentication

Certifications Are Not Transitive

A provider's certification covers that provider's controls, not Sterling's. For Sterling's own security posture and compliance status, contact your account team.

Newsletter

Insights on AI in wealth management

A short email when we publish something worth your time. Practical notes on AI, compliance, and running an advisory practice. No filler.

By subscribing you agree to receive the RK Sterling newsletter. Unsubscribe anytime.