Current security controls
- Encrypted transport over HTTPS/TLS.
- Authenticated access via Google OAuth.
- Per-account data isolation with row-level security policies.
- Application-level encryption for sensitive fields before database writes.
- No sale of personal or financial data.
- Security updates and dependency maintenance as part of regular releases.
Vulnerability reporting
If you discover a security issue, please report it privately and include clear reproduction steps. Do not post exploit details publicly before we have had reasonable time to investigate and fix the issue.
- Preferred reporting path: contact us through the in-app support channel.
- Public reference file:
/.well-known/security.txt. - Target response time: initial acknowledgement within 72 hours.
What is next
We continue improving account security and transparency with better auditing, stronger monitoring, and periodic hardening of infrastructure and application controls.