Built for financial data

Security

Footnote limits what it can do with your money and protects the data needed to show its work.

Updated August 26, 2026

Read-only by design

Footnote uses read-only financial connections. It cannot move money, place trades, or change an account at your bank.

Data protection

  • Public services and provider connections use HTTPS.
  • Hosted financial-connection records are encrypted at rest.
  • Production access follows least-privilege roles.
  • Authentication and financial data are scoped to the signed-in user.
  • A shared invitation opens only its group—not private bank activity.

Account controls

Footnote supports platform authentication, session management, institution disconnect, and account deletion. Keep your device, Apple or Google account, email, and passcode secure.

How Footnote is maintained

Dependencies are scanned in continuous integration, source changes receive automated security analysis, and operational controls are reviewed after material architecture or data-flow changes.

Report a vulnerability

Email sean@footnote.money with a clear description and steps to reproduce. Do not access another person’s data or disrupt the service while testing.

No system is completely secure. If Footnote confirms an incident that affects you, we will provide the information and actions required by applicable law.