Security Policy
Last Updated: January 1, 2026
Our Commitment to Security
The Veteran Alliance takes the security of your personal and financial information seriously. We employ industry-standard security measures designed to protect your data against unauthorized access, disclosure, alteration, and destruction. This Security Policy describes how we safeguard your information and the responsibilities we share with you.
Encryption & Data Transmission
All data transmitted between your browser and our servers is protected using Transport Layer Security (TLS 1.2 or higher). This ensures that your login credentials, personal information, and financial data are encrypted during transmission.
Sensitive data at rest — including Social Security numbers, account numbers, and passwords — is stored using AES-256 encryption. Passwords are never stored in plain text; we use industry-standard hashing algorithms with salting.
Authentication & Account Security
We support multi-factor authentication (MFA) for all accounts. Internal staff members are required to use MFA. Members are strongly encouraged to enable MFA through their account settings.
- Sessions expire automatically after a period of inactivity
- Account lockout occurs after multiple failed login attempts
- Password requirements enforce complexity and length standards
- Login events are logged and can trigger anomaly alerts
Infrastructure Security
Our platform runs on Amazon Web Services (AWS), which maintains multiple industry certifications including SOC 1/2/3, ISO 27001, and PCI DSS compliance. Our infrastructure uses:
- Web Application Firewall (WAF) to block malicious traffic
- DDoS protection at the network and application layers
- Virtual Private Cloud (VPC) isolation for database and backend services
- Automated vulnerability scanning and dependency monitoring
- Continuous security monitoring with CloudWatch and alerting
Access Controls & Employee Security
Access to member data is restricted on a need-to-know basis. All employees and contractors undergo background checks and security training before receiving system access. Role-based access controls (RBAC) ensure that staff members only access the data necessary for their job function.
All access to production systems is logged and auditable. Access rights are reviewed regularly and revoked immediately upon termination or role change.
Incident Response
In the event of a security incident affecting your data, we will notify you in accordance with applicable state and federal breach notification laws. Our incident response team is available 24/7 to detect, contain, and remediate security incidents. A detailed incident log is maintained and used to improve our security posture.
Your Security Responsibilities
Security is a shared responsibility. To protect your account:
- Use a strong, unique password for your VAB account
- Enable multi-factor authentication in your account settings
- Never share your login credentials with anyone
- Log out when using shared or public computers
- Keep your contact information current so we can reach you if suspicious activity is detected
- Report suspicious communications that claim to be from The Veteran Alliance
Phishing & Social Engineering
The Veteran Alliance will never ask for your password, full Social Security number, or full account number via email, text message, or phone call. If you receive a suspicious communication claiming to be from us, do not click any links. Report it to security@theveteranalliance.com.
Responsible Disclosure
If you discover a security vulnerability in our systems, please report it responsibly to security@theveteranalliance.com. We take all reports seriously and will work to address verified vulnerabilities promptly. We ask that you do not publicly disclose the vulnerability until we have had an opportunity to investigate and remediate it.
Contact Our Security Team
For security concerns or to report an incident:
Email: security@theveteranalliance.com
Phone: (833) VET-LNDR (ask for Security Team)
