---
title: "Financier security"
description: "How connecting your bank to Financier works, what we keep and how it is protected, who can see it, and how to delete it. Plain language, and only what is true today."
canonical: https://financier.sh/security
updated: 2026-10-02
---

# Financier security

How connecting your bank to Financier works, what we keep and how it is protected, who can see it, and how to delete it. Plain language, and only what is true today.

## Connecting your bank

- You connect through Plaid, the service many finance apps use. You sign in to your bank in Plaid's window, or on your bank's own site.
- Your bank username and password go to Plaid or your bank, never to Financier. We never see or store them.
- Plaid gives us a token that lets us read your accounts. You can cut it off at any time (see Deleting your data).

## Read-only: we cannot move money

Financier asks Plaid for one product: Transactions, which is balances and transaction history. We do not request account and routing numbers or any payment product, so Financier has no way to move money, pay bills or open accounts.

## What we store

| | |
| --- | --- |
| Bank access token | Encrypted with AES-256-GCM. The key is kept apart from the database. |
| Your accounts | Bank and account names, the last four digits, balances, and up to two years of transactions. |
| Your choices | Categories you set, your income settings, and your plan. |
| Sign-in | Your email and name. Passwords are stored only as a slow one-way hash; Google sign-in stores no password. Two-step sign-in secrets and backup codes are encrypted. |
| Keys you create | API keys are stored only as a hash and shown once. Webhook secrets are encrypted. |
| Activity | A log of syncs and changes on your account, kept for 90 days. |

## Who can see it

- You. Every request is checked against your account; one account cannot read another's data.
- Programs you allow: an API key you create (full access to your account) or an app you approve (read, or read and write). Revoke either under Settings, Developer.
- Financier's operator, who can reach the database to run the service. Admins see who has an account and how many banks it has connected; no admin screen shows balances or transactions.
- Service providers, only for what they do: Plaid (bank connection), Railway (hosting), TypeSafe (suggests categories from merchant names, the bank's descriptions of those charges and typical amounts; not your email or account details), Resend (invites, email confirmations and password resets).

## Signing in

- All traffic is HTTPS, and browsers are told to use nothing else.
- Session cookies cannot be read by scripts, and other sites cannot use them to make changes to your account.
- Repeated wrong passwords are slowed down. Passwords need at least 10 characters.
- You confirm your email before you can sign in with a password. A Google sign-in joins an existing account only when both Google and Financier have confirmed the address.
- Two-step sign-in: turn on an authenticator-app code under Settings, Account, with 10 single-use backup codes. Google sign-in uses Google's own second step.
- A forgotten password is reset by an emailed link that works once, for an hour, and signs out every session. Asking for one never reveals whether an email has an account.
- Accounts are invite-only for now.

## Deleting your data

| | |
| --- | --- |
| Disconnect a bank | Accounts, Disconnect. We tell Plaid to revoke the token, then delete it with that bank's accounts and transactions. |
| Delete your account | Settings, Delete account. Every bank is revoked at Plaid, then your data, sign-in, API keys and connected apps are deleted at once. |

If Plaid cannot be reached, nothing is deleted and you are told, so a bank is never left connected to an account that is gone.

The database is backed up daily (each copy kept 6 days) and weekly (each kept a month), so deleted data is gone from backups within a month.

## Where it runs

| | |
| --- | --- |
| Hosting | Railway, in the United States (US West). |
| DNS | Cloudflare. Traffic does not pass through Cloudflare. |
| Encryption in transit | TLS from your browser to our servers, and from us to Plaid. |

## What we do not do

- Sell your data, or share it for advertising.
- Show ads.
- Keep your data after you delete your account, beyond backups that age out within a month.
- Hold any security certification. We would rather tell you that than imply one.

## Report a vulnerability

Email security@financier.sh. Tell us what you found and how to reproduce it; please do not access other people's data or disrupt the service. We reply, fix, and credit you if you want.

- [security.txt](https://financier.sh/.well-known/security.txt)
- [Privacy policy](https://financier.sh/privacy)

## Security review, 2 October 2026

What we checked, what we found, and what we fixed.

Reviewed: bank token storage and key handling, sign-in, sessions, API keys, OAuth and agent access, admin tools, every API route's account checks, database queries, webhooks in and out, HTTP headers, rate limits, logging, dependencies, the code history for leaked secrets, and account deletion.

| | |
| --- | --- |
| Secrets in logs | High, fixed. A failed call to Plaid could write Financier's Plaid secret and a bank token into server logs. Errors now carry only Plaid's error code. |
| Deleting a removed bank | Medium, fixed. A bank already removed at Plaid blocked disconnecting it and deleting the account. It now counts as revoked. |
| Sign-in redirect | Medium, fixed. A crafted sign-in link could send you to another site after signing in. |
| Browser protections | Medium, fixed. Added HTTPS-only (HSTS), a content security policy, and refusal to be framed by other sites. |
| Email verification | Medium, fixed. Email addresses were not confirmed, so an account made first with someone's address could be joined by their later Google sign-in. Password accounts now confirm their email before signing in, and Google joins only confirmed accounts. |
| Sandbox connections | Low, fixed. Sandbox connections (synthetic data) could reuse an id after a restart and collide across accounts. Ids are now unique, and a connection can never move to another account. |
| Smaller hardening | Low, fixed. Webhooks refuse more private and reserved network addresses, and connect only to the address that was checked. Plaid's signing keys are trusted only until Plaid expires them, and invented key ids cannot make us call Plaid. Writes started by other sites are refused. Sign-in limits no longer depend on server settings. Test-only sign-in is refused on a public address. |
| Added | Two-step sign-in, password reset by email, and daily and weekly database backups. |
| No issue found | Token encryption, account checks on every route, database queries, Plaid webhook signatures, outbound webhook signing, admin access, secrets in code history, and known vulnerable dependencies. |
