Security
Sensitive by default.
Household finance data deserves boring, careful engineering — not marketing theater.
Controls in product
- Encrypted provider tokens at rest with application keys
- Session auth, passkeys, and optional MFA surfaces
- Expiring API tokens with explicit scopes and revocation
- Household isolation in Postgres with application access patterns
Operational direction
Production hosting targets AWS Route 53 DNS, CloudFront, and least-privilege accounts for staging vs production. Database: managed Postgres (Neon today) with pooled connections. Secrets stay out of git and client payloads.