Read-only by design
Footnote uses read-only financial connections. It cannot move money, place trades, or change an account at your bank.
Data protection
- Public services and provider connections use HTTPS.
- Hosted financial-connection records are encrypted at rest.
- Production access follows least-privilege roles.
- Authentication and financial data are scoped to the signed-in user.
- A shared invitation opens only its group—not private bank activity.
Account controls
Footnote supports platform authentication, session management, institution disconnect, and account deletion. Keep your device, Apple or Google account, email, and passcode secure.
How Footnote is maintained
Dependencies are scanned in continuous integration, source changes receive automated security analysis, and operational controls are reviewed after material architecture or data-flow changes.
Report a vulnerability
Email sean@footnote.money with a clear description and steps to reproduce. Do not access another person’s data or disrupt the service while testing.
No system is completely secure. If Footnote confirms an incident that affects you, we will provide the information and actions required by applicable law.