Security

You are trusting this application with a picture of your whole financial life. This page says how that picture is protected, what anyone can check for themselves, and how to tell us if you find a weakness.

No bank credentials, anywhere

This application never connects to your bank, and never asks for a bank username, password or access token. Every figure in it is one you typed in or uploaded yourself. There is no data aggregator in between, so there is no stored bank access that could leak, and no way for anyone who got into your account here to move money.

Encrypted in transit and at rest

  • Everything travels over HTTPS. Browsers are told to refuse a plain HTTP connection to this site for a year after any visit.
  • Sensitive fields — account names, balances, amounts and similar values — are encrypted at rest in the database. The keys are held in Azure Key Vault, separately from the data. When you are signed in, a field that is stored encrypted says so beside its label.
  • Your password is stored only as a salted, slow one-way hash, never in a form anyone can read back.

Signing in

  • Passwords must be at least 12 characters, and a password that appears in a public list of breached credentials is refused. Only the first five characters of its hash are ever sent to the checking service, so the password itself never leaves this application.
  • Two-factor sign-in with an authenticator app, with one-time recovery codes in case you lose your phone. Once it is on, it is asked for whether you sign in with your password, with Microsoft or in the mobile app.
  • Passkeys let you sign in with your device's fingerprint, face or PIN instead of a password. That never leaves your device; the application only stores a public key, which cannot sign anyone in on its own. A passkey is two factors by itself — the device, and what unlocks it — so it does not also ask for a code.
  • After 5 wrong passwords, an account is locked for 15 minutes. An address with no account behind it answers the same way, so guessing cannot reveal who has an account here.
  • A session ends after 12 hours without use, and "Keep me signed in" is off unless you choose it. Changing your password signs out every other session, and a password-reset link stops working after two hours.
  • The mobile app keeps its sign-in in your phone's secure storage, and can be locked behind your device's own fingerprint, face or passcode.

Who can see your data

  • You, and nobody else unless you invite them. Household sharing lets you give someone view-only or view-and-edit access; you choose which, you can remove it at any time, and every change they make is recorded where you can read it.
  • Administrators must use two-factor sign-in to reach any administration screen at all.
  • The application's own logs record what happened and to which record, never your amounts, names or descriptions.
  • No one else. There is no advertising, no third-party analytics or tracking, and no session recording, and your data is never sold or shared with data brokers. The Privacy Policy has the full detail.

Your data, your call

  • You can download everything you have entered at any time, as a spreadsheet and as a machine-readable file.
  • Closing your account erases your financial data immediately and permanently. A single record you delete is removed for good 30 days later, so an accident can still be undone on request.

Independent security checks

Three free public scanners grade how this site is served. On 2 October 2026 each gave its highest grade:

  • Mozilla HTTP Observatory: A+, with all 12 tests passed. It checks the content security policy, cookies, HTTPS enforcement and the other browser protections.
  • Qualys SSL Labs: A+, with no warnings. It checks the HTTPS certificate, the protocol versions and the encryption on offer.
  • securityheaders.com: A+. It checks the security headers every response carries.

These grades cover how the site is delivered to your browser. They are not an audit of the application's code or its hosting; no independent audit has been done.

Reporting a security problem

If you find a security weakness in this application, please write to support@manageyourmeans.com with "Security" in the subject. Say what you found, how to reproduce it, and what someone could do with it. Please don't include anyone else's personal data.

What you can expect

  • An acknowledgement within three business days.
  • Updates as the report is assessed and fixed, and a note when the fix is live.
  • Credit by name when the fix is announced, if you would like it.
  • No bug bounty: the application is free and earns nothing, so there is no payment for reports. They are still very welcome.

Researching in good faith

Manage Your Means LLC will not pursue legal action against research done in good faith that follows these rules:

  • Test only against an account you created yourself, or against demo mode.
  • Don't access, change or delete anyone else's data. If you reach some by accident, stop, don't keep it, and say so in your report.
  • No denial-of-service or load testing, no spam, and no social engineering of the operator, users or hosting providers.
  • Give the problem a reasonable time to be fixed — 90 days, or sooner once a fix is live — before you publish anything about it.

The machine-readable contact details are at /.well-known/security.txt.