Security

What we do with your deals, in plain words. If a claim is not on this page, we are not making it.

Your account

  • Sign in with a password or an emailed link. Passwords are at least 10 characters and are stored hashed by the authentication service; we never see them.
  • Two-factor authentication with an authenticator app, turned on from Settings › Security and asked for on every new sign-in.
  • Active sessions are listed in Settings › Security, and you can sign out every other device from there.
  • Export everything you own as JSON at any time, and request deletion of everything: your account, every account you own and every deal in them, within 30 days of the request, cancellable until then.

Your data

  • Every table is protected by row-level security in the database, in force from the first migration: a user reads only their own profile and the accounts they belong to, and this is tested on every build.
  • Deals are never used to train models.

What we do not claim yet

Sharing is not live in the product yet. The rule that a recipient can never write to the sender’s model is already enforced in the database and in the calculation engine, with tests on every build, and it moves up this page once you can send a share.

When it does, it will be claimed exactly as far as it goes. A withheld section is absent from the recipient’s copy, and every figure it would state is removed on our servers before that copy is built — both from what we send them and from the rows their own session is allowed to read — so the decision is never one the recipient’s browser could be talked out of. That is a rule about what the model states to them. It is not a claim that a withheld figure cannot be worked out: a recipient given the operating statement and the debt can derive the equity return, and the methodology page sets out how, and what stays out of reach.

A SOC 2 report is claimed only once an auditor is engaged.