Vendor Due Diligence

Trust & Due Diligence Center

Wealthtender maintains a complete set of written information security, privacy, and business continuity policies, reviewed annually and available on request. This page is the source for compliance and infosec teams evaluating Wealthtender as a service provider.

Calendar Year 2026
A+
2026 Pentest Grade
ISO 27001
Certified Hosting
$1M
Cyber Coverage

Security Posture

 

A+

Independent Penetration Test & Vulnerability Assessment

Astra Security, CREST certified and CERT-In empanelled, using OWASP WSTG methodology. Conducted March 17 to April 8, 2026. Automated full scan plus manual penetration test. Zero critical and zero high findings, with all medium findings remediated and verified.

View live security posture →

Hosting Infrastructure

WP Engine, which holds ISO/IEC 27001:2022 certification for its Information Security Management System and is SOC 2 compliant, with continuous vulnerability monitoring, edge protection, and multiple automated backups daily with point in time recovery.

Payment Processing

Handled entirely by Chargebee, a PCI-DSS Level 1 Service Provider and SOC 2 compliant platform. Wealthtender does not store payment card data.

Threat Monitoring

Weekly review of hosting provider vulnerability notifications with a proactive patch management program and documented remediation process.

Availability

99.5% uptime SLA. Planned maintenance windows are brief, under two minutes, and scheduled outside business hours.

Insurance Coverage

Cyber and Errors & Omissions coverage placed through Vouch. Certificates of insurance are available on request.

Coverage AreaLimitNotes
Policy Aggregate$1,000,000United Specialty Insurance Company via Vouch
Network Security Liability$1,000,000Per occurrence
Privacy Liability$1,000,000Includes regulatory liability
Breach Response Costs$500,000Includes rogue employee endorsement
Data Incident Restoration$500,000

Common Due Diligence Questions

 

Wealthtender collects a name, which is optional, and an email address when a consumer requests contact with an advisor or submits a review. That information is routed directly to the advisor. Wealthtender does not collect Social Security numbers, government identifiers, financial account numbers, account credentials, or any other sensitive personally identifiable or nonpublic personal information.
No. Wealthtender has not experienced a security breach since the company was founded in 2019.
Wealthtender is not a covered institution as defined under Regulation S-P, and does not collect or maintain sensitive customer information as the rule defines it. Wealthtender has nonetheless adopted the rule’s 72-hour service provider notification standard voluntarily. Our Incident Response Policy commits Wealthtender to notifying an affected subscriber firm as soon as possible, and in no event later than 72 hours after becoming aware of an incident involving unauthorized access to information relating to that firm, its personnel, or its clients.
No. Wealthtender does not offer interactive email or SMS functionality, and there is no mobile application. When a consumer submits a contact request or a review, a notification email is sent to the advisor. Advisors who wish to respond must do so from their own email system, which keeps those communications within the firm’s own books and records.
At least annually. Each policy carries a version number, shown in the Policy Library above, so the currency of any document can be confirmed at a glance.
Yes. Wealthtender maintains a one-page vendor due diligence overview summarizing security posture, data and privacy practices, insurance coverage, and business continuity. Email yourfriends@wealthtender.com and we will be happy to send it, along with any additional documentation your review requires.

Need something not listed here?

Additional documentation, including certificates of insurance, third-party security rating reports, and completed due diligence questionnaires, is available on request. Brian Thorp, Wealthtender’s founder and CEO, is also available to join a call with your compliance or vendor management team.

Request Documentation Schedule a Call