PRIVATE BY DESIGN. PRACTICAL BY DEFAULT.
FinHealth uses layered safeguards to protect account access and keep user-owned financial records separate.
Draft for review: this page is a product-specific plain-language summary, not legal advice or final legal terms.
ACCOUNT ACCESS
Authentication protects dashboard routes, and optional authenticator-app checks can protect sensitive account changes.
DATA PROTECTION
User-owned data is queried with ownership checks, sensitive fields use encryption helpers, and balance-moving actions use validated server-side transactions.
REPORTING A SECURITY ISSUE
Do not publish sensitive details in a public issue. Use the repository contact path to request a private reporting channel when a vulnerability may put people at risk.