FundWisr™ Security and Trust Center
1. Purpose
This Security and Trust Center Policy explains how FundWisr approaches information security, platform resilience, responsible disclosure, vendor oversight, artificial-intelligence processing, data protection, incident response, and customer trust.
It supplements the FundWisr Terms of Service, Privacy Policy, Cookie Notice, Acceptable Use Policy, AI Transparency Notice, Data Retention Policy, and related disclosures.
The public Trust Center may describe only controls that are currently implemented, reasonably verified, accurately scoped, and supported by evidence. Planned controls must be labeled Planned, In Progress, or Targeted.
2. Security Commitment
FundWisr may process confidential operational, financial, governance, funding, program, workforce, property, and strategic information. Impctrs Management Group, LLC maintains a security program designed to identify and govern risk, limit collection and retention, restrict access, secure development, monitor suspicious activity, manage vendors, respond to incidents, and maintain recoverability.
No platform can guarantee absolute security. FundWisr must never be described as unhackable, breach-proof, risk-free, or completely secure.
3. Security Framework
FundWisr's program should be organized around the NIST Cybersecurity Framework 2.0 functions:
- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
FundWisr may also use relevant guidance from CISA Secure by Design, OWASP ASVS, OWASP Top 10, and applicable NIST publications. Use of a framework does not mean certification or formal compliance.
4. Data Protection
FundWisr uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, alteration, disclosure, loss, or destruction. No security program can eliminate all risk.
5. Encryption
FundWisr encrypts supported data in transit using current transport-layer security protocols and uses encryption at rest for supported production databases, storage systems, and backups through approved infrastructure providers.
6. Authentication and Account Security
FundWisr should support secure password handling, multifactor authentication, session expiration and revocation, rate limiting, credential-stuffing defenses, account recovery, password-manager compatibility, secure invitations, and administrator role management.
Customers are responsible for protecting credentials, enabling MFA where available, reviewing access, removing former personnel, and reporting suspicious activity promptly. This does not eliminate FundWisr's responsibility to maintain reasonable security.
7. Access Control
FundWisr must apply least privilege through role-based access, workspace isolation, row-level security, privileged-access review, production restrictions, access logging, offboarding, and environment separation.
Support personnel should not have unrestricted access to Customer Content. Access must be limited to authorized purposes such as support, operations, incident investigation, legal compliance, maintenance, or customer instructions.
8. Workspace and Tenant Isolation
FundWisr uses logical access controls and testing designed to separate customer workspaces and restrict access to authorized users.
9. Application Security
FundWisr should maintain a secure software-development lifecycle covering security requirements, threat modeling, code review, dependency management, secrets scanning, static and dynamic testing, authorization testing, input validation, secure APIs, remediation, release controls, rollback, and change logging.
10. AI Security and Data Handling
FundWisr applies access, configuration, and data-handling controls designed to limit AI processing to authorized purposes. AI outputs may still contain errors, and users should not submit unnecessary sensitive information.
FundWisr does not use identifiable Customer Content, prompts, or outputs to train generalized artificial-intelligence models, and does not authorize its AI providers to do so, unless the applicable customer gives separate affirmative opt-in consent.
11. Secure File Handling
Uploaded files and generated documents must not be public by default.
12. Payment Security
FundWisr uses an approved payment processor to process subscription payments. FundWisr does not intend to store complete payment-card numbers or card verification codes in its application databases.
16. Vendor and Subprocessor Security
FundWisr must evaluate vendors that process customer or personal information. Review must address purpose, data categories, access, encryption, retention, deletion, incident notice, certifications, subcontractors, continuity, geographic processing, AI training, contracts, and termination support.
A vendor's certification does not automatically make FundWisr certified.
17. Data Retention and Deletion
FundWisr retains information for documented operational, contractual, legal, security, and customer-directed purposes. Eligible Customer Content is generally scheduled for deletion or deidentification from active systems after the applicable retention period, while limited billing, consent, security, legal, and backup records may remain as described in the Privacy Policy and Data Retention Policy.
19. Availability and Resilience
FundWisr designs its infrastructure and operating procedures to support availability and recovery. Planned maintenance, provider failures, cyber events, software defects, and other disruptions may still occur.
20. Incident Response
FundWisr must maintain a written incident-response plan covering preparation, detection, triage, containment, eradication, recovery, evidence preservation, legal and privacy review, communications, and post-incident improvement.
FundWisr maintains an incident-response process designed to investigate, contain, remediate, and communicate material security incidents in accordance with applicable obligations.
21. Security Incident Notifications
When notification is required, communications should state what happened, relevant dates, information involved, actions taken, recommended customer actions, support contact, and updates as reasonably available.
22. Security Reporting and Responsible Disclosure
If you believe you have identified a security vulnerability affecting FundWisr, please report it responsibly to support@fundwisr.ai or use https://www.fundwisr.ai/security/vulnerability-disclosure.
Ask reporters not to access unrelated data, alter or destroy data, disrupt availability, use social engineering, deploy malware, or publicly disclose before a reasonable investigation period.
23. Security Certifications and Reports
FundWisr is developing its security program against recognized security practices. FundWisr should not be represented as SOC 2 certified, ISO 27001 certified, HIPAA compliant, or independently audited unless and until the applicable assessment has been completed and the scope is stated.
24. Customer Security Documentation
Qualified customers may receive a security overview, architecture summary, subprocessor list, data-flow summary, security questionnaire, penetration-test summary, continuity summary, DPA, or reports when available.
25. Customer Security Responsibilities
Customers should use authorized accounts, enable MFA, protect credentials, limit administrator access, remove former users, verify exports and sharing, avoid unnecessary sensitive uploads, maintain current devices, and report suspicious activity.
40. Security Contact
Security email: support@fundwisr.ai
Security-report form: https://www.fundwisr.ai/security/vulnerability-disclosure
Status page: https://www.fundwisr.ai/status
Trust Center: https://www.fundwisr.ai/security
Mailing address: 830 N John Young Parkway, Kissimmee, FL 34741
FundWisr™ is operated by Impctrs Management Group, LLC under license from Mzrik Innovations, LLC. © 2026 Mzrik Innovations, LLC. All rights reserved. FundWisr™ and its proprietary frameworks, scoring systems, methodologies, platform content, software, and related intellectual property are owned by Mzrik Innovations, LLC. Technology developed by AI Arkitech, LLC.