Security and responsible reporting
Effective September 14, 2026 · Version 2026-09-14
Current protections
Financial records are restricted by signed-in user and database access policies. Provider secrets stay on the server; Plaid connection tokens use authenticated encryption in application storage. The app uses HTTPS and does not cache financial pages for offline access. Administrative authenticator MFA has been verified on GitHub, Vercel and Supabase. Dependency alerts and automated checks help identify known software issues. These controls do not constitute an independent security certification.
Limits you should know
Consumer MFA is not currently offered by this app. Email verification is not the same as MFA. We have not completed an independent penetration test or comprehensive legal/compliance certification. Authorized service operators may need access for support or operations. There is no guarantee of 100% security.
Report a concern
Email the contact below with a description, affected page and time of a suspected problem. Do not email passwords, API keys, full account numbers, SSNs or other users’ records. If you find unintended access, stop and report it without copying or modifying other users’ data. This notice does not authorize intrusive testing, disruption or access to third-party systems. If a bank account is at risk, contact your bank directly as well.