Security

Your financial data is the most sensitive thing you trust us with.

We treat it that way — with bank-grade encryption, third-party audits, and a security-first culture.

Six pillars of TinSuite security

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Bank tokens encrypted with keys we control, not Plaid's.

Access controls

Bcrypt password hashing (cost 12). 2FA + 10 backup codes. Account lockout after 5 failures. Session list + remote sign-out.

Zero-trust networking

Services isolated by Docker networks + nginx whitelist. No cross-tenant data exposure.

Auditable by design

Immutable audit log of every sensitive action. Available on Business plan with 7-year retention.

Reliable hosting

Hetzner (Germany), 99.9% uptime SLA. Daily backups, 30-day retention, point-in-time recovery.

Compliance

SOC 2 Type II in progress. GDPR, CCPA, PIPEDA, Quebec Bill 64 compliant. PCI-aligned for payment paths.

Day-to-day

How we operate

Static analysis on every commit

GitGuardian secrets scan, npm audit, Snyk dependency scan, ESLint security rules.

Penetration tests yearly

Third-party pen-testers at HackerOne. Report summary published in our trust portal.

Bug bounty program

Pay up to $5,000 for critical, $1,500 high, $500 medium via [email protected].

Vendor + sub-processor reviews

Every sub-processor (Stripe, Plaid, Resend, etc.) DPA-vetted before integration.

72-hour breach notification

Per GDPR Art. 33. Customers notified before regulatory deadline if any personal data exposed.

Quarterly DR drills

Restore from backup into isolated environment, verify integrity, document RPO/RTO.

Certifications

Compliance status

SOC 2 Type II
In progress
Audit Q3 2026
GDPR
Compliant
Since launch
CCPA
Compliant
Since launch
PIPEDA / Bill 64
Compliant
Since launch

Found a vulnerability?

Responsible disclosure is appreciated. Email [email protected] with reproduction steps. We pay up to $5,000 for critical findings and respond within 24 hours.

Trust the platform with your books.

14-day Pro trial. No credit card. Bank-grade security from day 1.