Security
You are trusting us with the picture of your company’s money. Here is exactly how it is protected today — no badges, no claims we cannot show.
Access
Verified accounts
Accounts are created with email confirmation. Passwords must be at least 12 characters and are handled by our identity provider; we never store them.
Server-side authorization
Every page, export and action verifies your session on the server and resolves your organization from it — never from what the browser sends.
Roles
Only owners, admins, CFOs and treasury managers can change connected sources. Analysts and viewers are read-only.
No account enumeration
Sign-in, sign-up and password reset respond identically whether or not an email is registered.
Data
Tenant isolation
Every record carries its organization and environment, and every query is scoped by them. Identifiers from another organization match nothing.
Append-only evidence
Ledger journals, balance observations and audit events cannot be updated or deleted — the database rejects it.
Exact amounts
Balances are integers in each asset's smallest unit, stored with 78 digits of precision. No floating point is ever used for money.
Audit trail
Sign-ins, failed attempts, password changes and every change to connected sources are recorded with actor, time, IP and device.
Connections
Read-only
Wallets are watched, not controlled. Watch-only wallets are observed, never controlled; managed wallets only move funds through your policies and approvals.
No keys, ever
We never ask for private keys or seed phrases. Anyone who does is not us.
Fixed endpoints
Blockchain and price sources are configured by us; your input is never used as a URL to fetch, which blocks server-side request forgery.
Evidence for every number
Each balance keeps its source, block and time, so totals can be traced back to what the chain actually reported.
Web platform
Strict browser policies
A Content Security Policy forbids third-party scripts and framing; HSTS, no-sniff, referrer and permissions policies are enforced on every response.
Private by default
Console pages are never cached by browsers or proxies.
Forgery protection
Mutations run as server actions with origin checks; post-login redirects only accept same-site paths.
Not yet in place
Two-factor authentication and passkeys, an independent security audit, and production deployment hardening are on the roadmap. We will list them here only once they are done. To report a vulnerability, create an account and contact us from the console.