// SECURITY
Your data is protected by design.
ENCRYPTION & TRANSIT
- All traffic to FINXPLORER is protected with TLS in production (HTTPS).
- We do not store bank passwords. Account linking uses our aggregator’s OAuth / token flow.
- Application secrets and OAuth credentials are kept out of client code and managed server-side.
FINANCIAL CONNECTIVITY
- Bank connections go through a regulated data aggregator (Quiltt) with read-only access where supported — we never ask for your banking password on FINXPLORER itself.
- We do not initiate payments or move money on your behalf.
- We are designed to minimize direct exposure to sensitive credential flows.
PLATFORM CONTROLS
- Authenticated access is enforced for all protected routes — no data is exposed without a valid session.
- Tenant-level isolation ensures your data is never accessible to other customer accounts.
- Billing, authentication, and operational events are handled with explicit server-side controls and logged.
- Security improvements are an ongoing engineering responsibility, not a one-time checkbox.
WHAT WE DO NOT CLAIM
We do not currently advertise a completed SOC 2 audit. When that changes, we will say so clearly. Prefer honest controls over marketing language.
RESPONSIBLE DISCLOSURE
If you believe you have identified a security vulnerability, please contact us before disclosing it publicly.
Email: security@finxplorer.com
We review all legitimate reports promptly and appreciate responsible disclosure.
> LAST UPDATED: AUGUST 2026