---
title: "Financier Trust Center"
description: "Security, data protection and privacy controls for Financier, stated as they are, gaps included."
canonical: https://financier.sh/trust
updated: 2026-10-05
---

# Financier Trust Center

Security, data protection and privacy controls for Financier, stated as they are, gaps included.

- [Overview](#overview)
- [Data protection](#data-protection)
- [Infrastructure](#infrastructure)
- [Application security](#application-security)
- [AI and data use](#ai-and-data-use)
- [Subprocessors](#subprocessors)
- [Privacy](#privacy)
- [Incident response](#incident-response)
- [Vulnerability disclosure](#vulnerability-disclosure)

## Overview

Financier reads bank data through Plaid to build a personal budget. It cannot move money. Bank credentials never reach Financier. Bank access tokens are encrypted, every request is checked against the account it reads, and deleting an account revokes its bank connections and deletes its data.

| | |
| --- | --- |
| Contact | security@financier.sh |
| Last updated | 2026-10-05 |
| Last security review | 2 October 2026, internal. Fixes are listed in the changelog. |

## Data protection

| | |
| --- | --- |
| In transit | TLS 1.2 and 1.3 only, enforced with HSTS. |
| Bank access tokens | AES-256-GCM, application-level, with a key held outside the database. |
| Other secrets | Passwords: one-way hash. API keys: hashed, shown once. Webhook secrets and two-step secrets: encrypted. |
| Other data | Stored in the database without application-level encryption, under the hosting provider's storage controls. |
| Segregation | One database for all accounts. Every read and write is scoped to the signed-in account. |
| Access scope | Plaid Transactions only: balances and transaction history. No account or routing numbers, no payment products. |
| Backups | Daily, kept 6 days. Weekly, kept 1 month. |
| Retention and deletion | See the privacy policy: https://financier.sh/privacy. |

## Infrastructure

| | |
| --- | --- |
| Hosting | Railway, US West. |
| DNS | Cloudflare, DNS only. Traffic does not pass through Cloudflare. |
| Recovery | Restore from the latest backup: up to 24 hours of data loss. No recovery time is committed. |
| Availability | No uptime commitment and no public status page. |

## Application security

| | |
| --- | --- |
| Changes | Every change is a pull request that passes linting, type checks and tests (on SQLite and Postgres), deploys to a staging environment, and reaches production only by a release. |
| Dependencies | Checked against known vulnerabilities on every change. |
| Testing | Internal security review: 2 October 2026. No third-party penetration test yet. |
| Hardening | Content security policy, framing refused, cross-site writes refused, rate limits on sign-in and the API, outbound webhooks limited to public addresses. |
| Sign-in | Email and password (10 characters minimum, email confirmed), or Google where enabled. Two-step sign-in with an authenticator app and 10 single-use backup codes. Password reset by single-use link, valid one hour, ending every session. |
| Programs | API keys and approved apps act only on their account, within their scope, and can be revoked under Settings, Developer. |
| Activity log | Syncs, balance changes and edits, kept 90 days, readable through the API. |

## AI and data use

| | |
| --- | --- |
| Model training | Financier trains no models on user data. |
| AI vendors | TypeSafe suggests merchant categories from merchant names, the bank's descriptions and typical amounts. It receives no names, emails or account numbers. |
| Shared answers | A merchant's suggested category is reused for every account. A person's own categories are theirs alone. |
| Assistants you connect | An AI assistant connected over MCP or the API reads what its access allows, and its provider processes it under that provider's terms. |

## Subprocessors

| | |
| --- | --- |
| Plaid | Bank connections. |
| Railway | Hosting and database. |
| Resend | Email: invitations, confirmations, password resets. |
| TypeSafe | Merchant categorization. |
| Cloudflare | DNS. No user data. |
| Google | Sign-in, where enabled, for accounts that use it. |

Changes to this list are recorded in the changelog.

## Privacy

| | |
| --- | --- |
| Policy | https://financier.sh/privacy: what is collected, why, retention, deletion and data requests. |
| Location | Data is stored and processed in the United States. |
| Cookies | Sign-in cookies only. No tracking or advertising cookies. |

## Incident response

| | |
| --- | --- |
| Notification | People whose data a confirmed breach affects are emailed within 72 hours, with what happened and what to do. |
| Record | Incidents and their fixes are recorded in the changelog. |

## Vulnerability disclosure

| | |
| --- | --- |
| Report to | security@financier.sh |
| Include | What you found and how to reproduce it. |
| Safe harbor | Good-faith research that avoids other people's data, destruction and disruption, and reports promptly, is welcome; no legal action will follow it. |
| Response | Every report is answered. Fixes are recorded in the changelog and credited on request. |

- [security.txt](https://financier.sh/.well-known/security.txt)
- [Changelog](https://financier.sh/changelog)
