Trust
Security
1. Signing in
- Email sign-in links. You sign in with a link sent to your inbox. Each link works once and expires after 15 minutes, and asking for a new link cancels any earlier ones.
- Passwords are optional. If you set one, it is stored only as a salted bcrypt hash, never in readable form.
- Sessions end. A session lasts at most 30 days. You can sign out of every device at once, and changing your password also signs out your other devices.
- Repeated attempts are limited. Sign-in and account lookup requests are rate-limited to slow down guessing and abuse.
2. Who can see what
- Roles. Every workspace member is an owner, an admin or a crew member, and the server checks their role on every request, not just in the app’s screens.
- Separate workspaces. Every record belongs to a workspace, and requests can only reach records in the workspace you are signed in to.
- An activity trail. Changes are recorded with who made them and when, so owners and admins can review what happened.
- A safety net. Deleted records go to a trash first, and an owner or admin can restore them.
3. Infrastructure
- Encrypted in transit. All connections to the site and app use HTTPS.
- No direct exposure. The application server only accepts connections through a reverse proxy on the same machine. It is not directly reachable from the internet.
- Payments stay with Stripe. Card details are entered on Stripe’s pages and never touch our servers. Stripe is certified to PCI DSS Level 1.
- Limited access. Only authorized people can access production systems, and only when they need to.
4. Your part
- Protect your email account. Anyone who can read your email can sign in as you, so turn on two-step verification with your email provider.
- If you lose a phone or suspect someone else has access, use sign out everywhere.
- Remove people from your workspace when they leave your business.
- Don’t store sensitive information the app doesn’t need, such as ID numbers or full card numbers. See our Acceptable Use Policy.
- Export your data regularly so you always have your own copy.
5. If something goes wrong
If we discover a security incident that affects your personal information, we will investigate, contain it, and notify affected customers and authorities without undue delay, as the law requires.
6. Reporting a vulnerability
We appreciate help from security researchers. If you think you’ve found a vulnerability, email security@staging.expenseapp.example with enough detail for us to reproduce it. We aim to acknowledge reports within 3 business days and to keep you updated while we work on a fix. Our contact details are also published at /.well-known/security.txt.
Guidelines
- Test only against accounts and workspaces you own, or have explicit permission to test.
- Don’t access, change or delete other people’s data. If you come across it, stop, and include only the minimum needed to show the issue in your report.
- Don’t run denial-of-service tests, spam, social engineering or physical attacks.
- Give us reasonable time to fix the issue before disclosing it publicly.
Safe harbor
If you make a good-faith effort to follow these guidelines, we will not take legal action against you or ask law enforcement to investigate you for your research, and we will treat it as authorized under our Terms. We don’t currently offer a paid bug bounty.