NestIQ WealthNestIQ WealthBack to site →
Security & Trust

Security of your investment, stated plainly.

This page describes the controls that are in place today, the assurances we do not yet hold, and how you can verify the important parts for yourself. It is maintained by NestIQ Wealth and is not an independent audit or certification.

Last reviewed: 4 August 2026.

Controls in place today

Authentication

Accounts are protected by email and password or Google sign-in, managed by our hosted authentication provider. Email addresses must be verified before an account can be used, and passwords are never stored by NestIQ Wealth in readable form.

Per-user data isolation

Every table holding your data enforces row-level security in the database itself. A request is only ever served rows that belong to the signed-in account — isolation is applied at the data layer, not only in the interface.

Encryption in transit and at rest

All traffic is served over HTTPS/TLS, and the managed database and file storage behind the app encrypt data at rest. This is provided by our cloud infrastructure provider.

Private document storage

Certificates and property documents are held in a private storage bucket. They are never publicly listable, and downloads are served through short-lived signed links generated for your session only.

Audit trails

Compliance actions keep a versioned history — uploads, replacements and restores are recorded with timestamps, so you can evidence what was held and when.

Payments handled by Stripe

Card details are entered directly with Stripe and never touch NestIQ Wealth servers. We store only a customer and subscription reference. Stripe is PCI DSS Level 1 certified as a payment processor; that certification is Stripe's, not ours.

Deletion and export

You can export your compliance records as PDF at any time and request account deletion from Settings, which removes your portfolio data and cancels any active subscription.

Server-side authorisation

Privileged operations run on the server behind an authenticated session check. Administrative capabilities are gated by roles held in a dedicated table, never by anything the browser can edit.

What we are — and are not — certified for

Security claims are only worth anything if they are accurate. Here is where we stand.

What we can evidence

  • Encryption in transit (TLS) and at rest on managed infrastructure.
  • Row-level security enforcing per-user data isolation in the database.
  • Private document storage with short-lived signed download links.
  • Verified email addresses before an account becomes usable.
  • Card data handled entirely by Stripe, never by our servers.
  • Versioned compliance history and an administrative audit trail.

What we do not claim

  • SOC 2 / ISO 27001. NestIQ Wealth does not currently hold either certification. Our underlying cloud providers maintain their own certifications, but that does not extend to us.
  • Independent penetration test. No third-party penetration test or security audit has been commissioned to date.
  • Multi-factor authentication. MFA is not yet available on NestIQ Wealth accounts. Signing in with Google means your Google account's 2-step verification applies to that sign-in.
  • “Bank-grade” or guaranteed security. We deliberately avoid that phrase. No provider can guarantee an absence of breaches, and we will not imply an assurance level we have not had independently verified.
  • FCA regulation. NestIQ Wealth is a software tool, not a regulated financial adviser. Nothing in the product is financial or legal advice.

Shared responsibility

Our infrastructure provider

Physical data centre security, platform patching, managed database and storage encryption, and network isolation.

NestIQ Wealth

Access rules, per-user isolation policies, authorisation on every server operation, secret handling, and accurate public statements about all of the above.

You

A strong, unique password, control of your email inbox, and care over who you share exported reports and documents with.

How to verify this yourself

You should not have to take a security page at its word. Each of these can be checked without our help.

  1. 1

    Check the connection

    Every page is served over HTTPS. Your browser's padlock shows the certificate issued for nestiqwealth.com — if it is missing or warns you, stop and contact us.

  2. 2

    Test the isolation yourself

    Create a second account and confirm that none of your first account's properties, documents or figures are visible. Isolation is enforced in the database, so this is a real test, not a UI check.

  3. 3

    Inspect a document link

    Copy a document download link and open it in a private window after a few minutes. It should expire, because links are signed and short-lived rather than public URLs.

  4. 4

    Confirm the payment surface

    At checkout the card form is hosted by Stripe. You can verify the domain of the payment frame and see the charge described on your Stripe receipt.

  5. 5

    Read the policies

    Our Privacy Policy, Terms of Service and Cookie Policy are versioned in the Legal Centre with effective dates and revision history.

  6. 6

    Ask us directly

    We will answer specific questions about data handling, sub-processors and retention in writing.

Reporting a vulnerability

If you believe you have found a security issue, please email support@nestiqwealth.com with the subject line “Security report”. Include the steps to reproduce and, where possible, a screenshot. We aim to acknowledge reports within two working days.

Please do not access, modify or download another customer’s data while testing, and give us a reasonable opportunity to fix an issue before disclosing it publicly. We do not currently run a paid bug bounty, but we will credit reporters who ask to be named.

Legal CentrePrivacy PolicyTerms of ServiceCookie Policy

This page is maintained by NestIQ Wealth to answer common security and privacy questions about the platform. It describes current practice rather than a contractual commitment, is not a certification, and is not independent verification. Where a control is provided by an infrastructure or payment partner, that partner’s certifications belong to them and are not claimed by NestIQ Wealth.