Security
How we keep your data safe
Finance holds personal money records, so we treat them carefully. Here is what we do today, in plain words.
We never touch your money.
Finance has no access to your bank. We never ask for bank logins, card numbers or your UPI PIN. Settling up opens your own UPI app; the payment happens there, not with us.
Passwords and sessions.
Passwords are stored only as bcrypt hashes, so we cannot read them. Your session lives in a secure, HttpOnly cookie that scripts cannot read and that expires after 30 days. Changing your password ends your older sessions. After 10 wrong passwords for one email within 15 minutes, login pauses for that email.
Your data is walled off.
Every request checks who you are and returns only your own records, or the shared records of groups you belong to.
Encrypted in transit.
Every page and API call uses HTTPS. Data at rest is stored with our database provider, Neon, which encrypts stored data.
The AI cannot act alone.
The assistant can read your records to answer you, but every change goes through a confirm card that only you can approve. We also limit how many requests each person can make, to protect the service from abuse. How we use AI
Invite links.
Group invite links use long random tokens. We store only a fingerprint (hash) of each token, links expire, and the person who made one can revoke it.
Deletion that actually deletes.
When you delete your account, you are signed out everywhere. After a 30-day grace period, your account and everything in it are permanently erased. How deletion works
Where your data lives.
The app runs on Vercel (USA) and stores data in a Postgres database on Neon (Singapore). Cloudflare provides our DNS only.
Report a security issue
Found a vulnerability? Email security@trackwithagent.com with steps to reproduce. Please give us reasonable time to fix it before sharing it publicly, and do not access other people's data, run denial-of-service tests or use automated scanners against production. We will acknowledge your report within 3 working days and keep you updated. We do not run a paid bug bounty yet, but we will thank you publicly if you would like.
Machine-readable contact: /.well-known/security.txt
We are a young company and do not hold security certifications yet. We will update this page as our practices grow.