Security & Contact Policy
Invesdors operates under SIX bLink participant obligations. This page discloses our security contacts, incident procedures, and responsible disclosure policy.
Official Contact Points
The following contacts are designated for fraud, technical issues, and complaint handling.
Fraud & Abuse
Report suspected fraud, identity theft, or unauthorized account access.
support@invesdors.chSecurity Vulnerabilities
Responsible disclosure of security vulnerabilities in our platform or APIs.
security@invesdors.chTechnical Issues & Claims
Payment disputes, technical failures, and service complaints.
technical@invesdors.chResponsible Disclosure Policy
If you discover a vulnerability in Invesdors, please report it responsibly.
Report privately first
Email support@invesdors.ch with a clear description of the vulnerability, steps to reproduce, and potential impact.
No public disclosure
Please do not publish or share details of the vulnerability until we have had 90 days to investigate and release a fix.
Response timeline
We will acknowledge receipt within 48 hours and provide a status update within 5 business days.
Safe harbor
Security researchers acting in good faith under this policy will not face legal action from Invesdors.
Incident Response Procedure
In case of a data breach or security incident affecting bLink-connected bank account data:
Immediate containment
Affected services are isolated or suspended. bLink connections may be temporarily disabled.
User notification (≤ 72h)
Affected users are notified via platform notification and email within 72 hours, per Art. 92 PSD2 / Swiss DSG Art. 24.
SIX notification
SIX Group is notified via the bLink Support Portal immediately upon detection of any incident affecting bLink data.
Regulator notification
FINMA or relevant authorities notified if required by applicable Swiss law.
Post-incident report
Root cause analysis and remediation documented and shared with SIX within 30 days.
Infrastructure & Data Security
Hosting
Infomaniak, Switzerland — application servers and databases run on Swiss infrastructure.
Data residency
All personal, financial, and identity data is stored and processed in Switzerland.
Encryption at rest
Sensitive fields such as IBANs and wallet key material are encrypted at the field level using AES-256-GCM before they reach the database.
Encryption in transit
All traffic is served exclusively over TLS with HSTS enforced; unencrypted requests are upgraded automatically.
Access control
Internal access to production systems and customer data is role-restricted and logged; investors and founders can only reach their own data through authenticated, permission-checked API routes.
Audit trail
Security-relevant and financial actions are recorded in an append-only audit log for compliance and incident review.
Backups
Databases are backed up on a regular schedule with off-server retention.
Penetration testing
Independent penetration testing is scheduled as part of our SIX bLink participant certification process.
bLink Consent Revocation
If you wish to revoke Invesdors' access to your bank account data via SIX bLink, you can do so at any time:
- 1.Log in to your Invesdors account → Settings → Privacy → Remove bLink connection.
- 2.Revoke directly in your bank's online banking: Settings → Connected Apps → Invesdors → Remove.
- 3.Your connection and all stored tokens will be deleted within 24 hours of your request.
Questions about this policy?
technical@invesdors.chLast updated: June 2026 · Invesdors · Version 1.0 · SIX bLink Participant D0550.DE.08