
Security
Milestones Retirement Insights is committed to protecting the confidentiality, integrity, and availability of the information entrusted to us. We maintain administrative, technical, and physical safeguards designed to protect customer information and support the secure operation of our services.
Customer data is encrypted in transit using industry-standard encryption protocols and is hosted within Microsoft Azure cloud infrastructure. Access to systems and customer information is restricted to authorized personnel based on business need and protected through role-based access controls and multi-factor authentication. Access permissions are reviewed periodically and removed when no longer required.
Milestones Retirement Insights utilizes security monitoring and endpoint protection technologies to help detect and respond to potential security threats. Security vulnerabilities identified through internal reviews, external assessments, or third-party testing are evaluated and remediated based on risk. We maintain documented policies and procedures covering areas such as access management, data protection, incident response, vendor management, and business continuity.
As part of our ongoing commitment to security and transparency, Milestones Retirement Insights maintains a public Trust Center and is actively progressing through a SOC 2 compliance program.
Security Vulnerability Reporting
If you believe you have identified a security vulnerability affecting a Milestones Retirement Insights system, product, or service, we encourage you to report it responsibly.
Please send reports to:
info@milestones-retirement.com
To assist our investigation, please include:
-
A description of the vulnerability
-
Steps required to reproduce the issue
-
The affected system, application, or URL
-
Any supporting screenshots, logs, or evidence
Milestones Retirement Insights will acknowledge receipt of vulnerability reports within five business days, investigate reported issues promptly, and work to remediate validated findings based on risk and impact. Where appropriate, we will communicate status updates to the reporting party throughout the investigation process.
We support good-faith security research and will not pursue legal action against individuals who act responsibly, avoid privacy violations or service disruption, refrain from accessing customer data unnecessarily, and provide reasonable time for investigation and remediation before public disclosure.
This policy applies solely to systems, applications, and services owned or operated by Milestones Retirement Insights.
How to Contact Us
To obtain access to your information, report incorrect information, file a complaint or to make any enquiries or comments about this Privacy Policy, contact us at: info@milestones-retirement.com