Your financial data is the most sensitive thing you'll trust us with. We treat it that way.
TLS 1.3 in transit. AES-256 at rest. Bank tokens encrypted with keys we control.
Role-based permissions, 2FA, SSO for Business. Every admin action logged.
Services isolated by network policy. No cross-tenant data exposure.
Immutable audit log of every sensitive action. Accessible on Pro+ plans.
Hetzner primary data center (Germany). Hourly automated backups, point-in-time recovery.
SOC 2 Type II audit in progress. GDPR and CCPA compliant. Aligned with PCI-DSS for payment paths.
Found a vulnerability? We reward responsible disclosure. Email [email protected]. Our PGP key is published at /security/pgp.
Current subprocessors: Hetzner (hosting), Stripe (payments), Plaid (banking), Resend (email), Cloudflare (DNS/CDN). Full list at /subprocessors. 30-day notice before adding new subprocessors.