No computer system has perfect security, but Empower uses industry standard security best practices, including:
- Encryption in transit and at rest
- Working with independent security researchers in a bug bounty program
- Making Empower secure by default to eliminate some of the most common attacks (e.g., using login codes instead of passwords)
- Static analysis of our code
- Automated alerts for vulnerabilities in third party code that we use
- Internally, using password managers and 2 factor authentication where appropriate
- Managing our infrastructure with code so that we can more easily roll out security patches
And, we have experience securing large systems. Our engineers have worked at banks and large tech companies like Google. They've led security reviews for Federal systems that manage tens of millions of people's healthcare data.
Beyond the purely technical aspects, Empower's model also has some security advantages. We are a nonprofit. We don't sell your data. And we're relational. From our perspective, if you didn't want to put in any real data and wanted to just use nicknames for everyone, that would work great!