Security at Seerian
How we protect your data, your team, and your integrations.
Enterprise authentication, out of the box.
Single sign-on (SSO)
SSO is provided via Clerk and supports all major SAML and OIDC identity providers. Administrators can configure domain whitelisting to restrict sign-in to verified company email domains and enforce SSO organization-wide, preventing password-based login for all members.
Multi-factor authentication
Seerian supports passkeys (FIDO2/WebAuthn) as a phishing-resistant second factor, alongside TOTP-based 2FA compatible with standard authenticator apps. MFA enrollment can be enforced at the organization level so that no member can access the platform without a second factor.
Device management
Users have full visibility into all active devices and sessions associated with their account. Individual sessions can be revoked on demand, and administrators can trigger credential rotation across the organization. Suspicious or unrecognized sessions are surfaced prominently in the account security dashboard.
Role-based access control (RBAC)
Access is governed by four roles (Admin, Manager, Member, and Viewer), each with progressively narrower permissions. Controls are applied across organization settings and billing, member provisioning and deprovisioning, workspace creation and configuration, portfolio visibility, and shared resources such as saved reports and alerts. Role assignments are auditable and can only be changed by Admins.
Where your data lives and how it's protected.
Hosting
Application infrastructure and all customer data are hosted in the European Union, across managed providers subject to EU data protection regulation. Named providers and their regions are listed in our subprocessor register, available on request.
Encryption
All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256. API keys and other credentials stored on your behalf are encrypted at the field level before persistence.
Data isolation
All customer data is logically isolated per organization. Strict application-layer tenancy controls ensure no cross-organization data access is possible.
Data retention
Customer data is retained for the duration of an active subscription. Upon account closure or subscription cancellation, all data is permanently deleted within 30 days. Data deletion can be requested at any time by contacting support.
Backups
Backups are automated and managed by our database providers, with point-in-time recovery allowing data to be restored to any point within the retention window. Backup integrity is verified automatically.
Read-only. Always.
Seerian is a portfolio monitoring and analytics platform. We require the minimum possible access to give you accurate data, and nothing more.
Exchange connections
When connecting an exchange, Seerian requests read-only API keys scoped to balance and trade history endpoints. We explicitly do not request, store, or use withdrawal permissions. Read-only keys cannot move funds under any circumstances. We recommend creating a dedicated API key for Seerian with only the permissions listed in our setup guide.
Wallet connections
Wallet integrations use public blockchain addresses only. We never request, handle, or store private keys, seed phrases, or any credential capable of signing transactions. Balance and transaction data is fetched directly from on-chain sources using the public address you provide.
| Action | Can do | Cannot do |
|---|---|---|
| View balances | Yes | — |
| View transaction history | Yes | — |
| Execute trades | — | Never |
| Withdraw funds | — | Never |
| Transfer assets | — | Never |
| Sign transactions | — | Never |
Who handles your data and why.
We use a small number of carefully selected subprocessors. Each is bound by a data processing agreement, hosted in the EU except where noted in the register, and subject to independent security audits.
We maintain a full subprocessor register covering each vendor, the data they process, their hosting region, and their certifications. We share it with customers and with prospects under evaluation, along with our DPA and completed security questionnaires.
Request the register at security@coinseera.com.
Where we are and where we’re headed.
Current controls
Seerian operates with SOC 2-aligned security controls across access management, change management, availability, and incident response. Internal policies cover:
- Acceptable use and information security policy
- Access control and least-privilege policy
- Vulnerability management and patch cadence
- Business continuity and disaster recovery
- Vendor risk management
- Employee security training (on hire and annually)
Roadmap
A formal SOC 2 Type II audit is planned. Enterprise customers requiring a timeline or audit scope details should contact their account manager or reach out to security@coinseera.com.
Security questionnaires
We can complete SIG (Standardized Information Gathering), CAIQ (Consensus Assessments Initiative Questionnaire), and custom security questionnaires. Requests are handled within five business days. Contact security@coinseera.com to initiate a request.
Report a vulnerability.
If you believe you have discovered a security vulnerability in Seerian, please report it responsibly. We take all reports seriously and commit to investigating and responding promptly.
Email your findings to security@coinseera.com. Please include a description of the vulnerability, steps to reproduce, and your assessment of impact. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.
Questions about our security posture?
Walk through our controls with the team during your demo, or reach out to security@coinseera.com.