Skip to content
Security & Privacy

Built for trust, from the database up.

A financial technology product demands the highest engineering bar. Here is exactly how your data is protected at every layer.

Encrypted, always & everywhere

Bank access tokens are encrypted at rest with military-grade AES-256-GCM encryption algorithms and strictly bound to your specific account ID. Data in transit requires TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers, eliminating any possibility of man-in-the-middle attacks.

Read-only banking protocols

We interface exclusively through Plaid using read-only API credentials. MoneyWealth AI can analyze account balances and incoming/outgoing transactions, but is structurally incapable of initiating transfers, issuing payments, modifying account credentials, or moving money.

Isolated database architecture

Every single database record is isolated at the physical storage layer using PostgreSQL Row-Level Security (RLS). Your financial data is programmatically unreachable from other tenant sessions—enforcing absolute defense-in-depth across our cloud cluster.

Zero-credential exposure

Session access tokens exist solely in volatile browser memory. Refresh tokens are stored strictly within httpOnly, Secure, SameSite cookies that are inaccessible to JavaScript, safeguarding against cross-site scripting (XSS) and token theft.

Hardened web security posture

Our web endpoints enforce strict Content Security Policies (CSP), subresource integrity verification, clickjacking prevention (X-Frame-Options DENY), MIME-type sniffing protection, and granular Referrer-Policy controls on every HTTP transaction.

Grounded & Private AI Engine

Advice AI utilizes retrieval-augmented generation (RAG) restricted strictly to your verified database context. The AI assistant cites specific transactions, does not train public models on your proprietary records, and cannot be prompt-injected into revealing external data.

Enterprise-Grade Data Protection & Architectural Integrity

Managing personal wealth requires an uncompromising approach to cybersecurity. From our database schema design to our browser session lifecycle, every component of MoneyWealth AI has been built according to zero-trust architecture principles. We treat user privacy not as a compliance checklist, but as our primary engineering constraint.

Zero-Trust Isolation Layer

Multi-tenant data isolation is guaranteed at the kernel and database layer via cryptographic account tagging and Row-Level Security, preventing any accidental data leakage across sessions.

Continuous Automated Audits

Our deployment pipelines automatically scan dependencies for Common Vulnerabilities and Exposures (CVEs), enforce static analysis security testing (SAST), and audit container configurations.

Security & Privacy Questions

Clear answers about our data custody, banking aggregators, and algorithmic privacy.

Does MoneyWealth AI sell or monetize user financial data?+

No, under no circumstances do we sell, rent, license, or monetize your personal or financial data to third-party advertisers, brokers, or marketing networks. Our business model is funded entirely by direct software subscriptions from our users, ensuring our incentives remain 100% aligned with your personal financial privacy and data protection.

Can MoneyWealth AI employees view my bank account credentials?+

No. Your bank credentials (usernames, passwords, and multi-factor authentication tokens) are entered directly into Plaid's secure embedded iframe and are never transmitted through or stored on MoneyWealth AI servers. We only receive an encrypted, tokenized identifier that allows read-only balance and transaction synchronization.

What security compliance and operational standards do you adhere to?+

Our infrastructure is hosted within SOC 2 Type II, ISO 27001, and PCI-DSS compliant cloud data centers. We implement automated dependency vulnerability scanning, continuous integration security gates, regular third-party penetration assessments, and automated offsite encrypted backups.

How can I permanently purge all my financial records?+

You can request complete data deletion at any time from your Account Settings. Triggering account deletion immediately revokes all banking tokens, disconnects your accounts from financial aggregator APIs, and permanently deletes all stored balance histories, transaction ledgers, and budget profiles from our primary databases.

Your data, your sovereign control

Export your records anytime in standard JSON or CSV files. Deleting your profile instantly disconnects all institutional connections at Plaid and triggers an irreversible purge from our operational storage.

Responsible disclosure & Bug Bounty

We proactively collaborate with independent security researchers and ethical hackers. If you believe you have discovered a vulnerability, please contact security@moneywealth.ai for rapid verification and remediation.