Security

How we protect the books

We encrypt customer data, limit access, monitor core services, and keep regular backups. Financial information should only be available to the people meant to see it.

Hands reviewing financial documents at a worktable

Encryption in transit and at rest

Customer data is encrypted in transit using modern TLS and at rest where supported by our infrastructure providers.

  • TLS for browser and API traffic
  • Encryption at rest where supported
  • Database backups managed in encrypted storage

Secure authentication

We use SuperTokens for session management with secure password hashing and rate-limiting on authentication endpoints.

  • SuperTokens session management
  • Modern password hashing via SuperTokens
  • Rate limiting on login attempts

Cloud hosting and backups

FinButler is hosted on managed cloud infrastructure with regular database backups and basic availability monitoring.

  • Availability monitoring on core services
  • Regular database backups
  • Managed cloud hosting

Code and dependency checks

Application development is informed by OWASP Top 10 guidance, with internal review and automated dependency scanning.

  • OWASP Top 10 considerations during development
  • Automated dependency vulnerability scanning
  • Internal code review on security-sensitive changes

Who can access your data

Role-based access control limits who can reach specific features and data inside an account.

  • Team role-based permissions
  • Session timeout protection
  • IP-based access logging

Data privacy

Your data belongs to you. We do not sell it. You can export or delete it.

  • No data selling
  • Data export
  • Account deletion available

How we handle security

Monitoring and incident response

We monitor core services for availability and unusual activity, and we operate documented incident response procedures.

  • Application and infrastructure monitoring
  • Automated alerting on key services
  • Documented incident response procedures

Internal access controls

Internal access to production systems is limited to people who need it for their role and is tracked through our access management process.

  • Principle of least privilege for production access
  • Access reviewed when responsibilities change
  • Ongoing security awareness for the team

Report a security issue

Email security@finbutler.ai. Include a description, steps to reproduce, potential impact, and a suggested fix if you have one. We acknowledge receipt within 48 hours.