Data Privacy

Why Privacy Vault
is different

A normal application database keeps your name and email in the same tables as everything else. It is quick to build, and one breach of it exposes every field together. Margin keeps those fields in a Privacy Vault instead, behind their own encryption keys, so a leak of the main database hands over nothing that identifies you.

The traditional approach

In a conventional setup your name, email, portfolio holdings and transaction history all live in the same database tables, and a single SQL query joins them. The join is convenient for engineers, and it means:

  • A compromised database credential exposes everything at once.
  • An insider with read access to the database can see your personal details alongside your financial data.
  • Any misconfigured query or API can accidentally leak PII alongside non-sensitive records.
  • Regulatory audits are harder, because no boundary separates sensitive data from the rest.

-- Traditional: everything in one place

SELECT u.name, u.email, p.stock, p.quantity

FROM users u

JOIN portfolios p ON u.id = p.user_id;

-- One breach = name + email + holdings exposed together

How Privacy Vault works

A Privacy Vault (we use Databunker) moves personally identifiable information, meaning your name, email and phone, out of the main database entirely. It holds them in an isolated encrypted store with its own access controls and its own encryption keys.

Your main database only holds a random token that references the vault record. The token means nothing on its own, and without the vault's separate keys it cannot be worked back to your identity.

-- With Privacy Vault: PII is isolated

portfolios table:

user_token: a3f8c2d1-... (random, meaningless)

stock: RELIANCE

quantity: 50

vault (separate system, separate keys):

token: a3f8c2d1-...

name: [encrypted]

email: [encrypted]

-- Breach of main DB = tokens with no identity attached

  • PII is encrypted with keys that are separate from your application database.
  • Access to portfolio data does not grant access to personal identity, because the two are held apart.
  • The vault maintains its own audit log of every access to sensitive fields.
  • Data deletion requests (right to erasure) are handled at the vault level without touching the main database.

Side by side

Scenario Traditional DB Privacy Vault
Database breach Name, email & holdings exposed Only meaningless tokens exposed
Insider access Full user records visible PII requires separate vault key
Data deletion request Must hunt & purge across tables Deleting the vault record is enough
Audit trail for PII access Manual logging or none Built-in per-field access log
Regulatory compliance Engineer effort required Isolation built into the storage layer

What this means for you

Someone who broke into Margin's database would find portfolio records tied to random tokens, with no names and no emails to attach them to.

Your broker login credentials are never stored at all, and trade files you upload are processed in memory and never persisted to third-party systems. Privacy Vault covers the only personal data we do hold.