How it's built
How FinanceSight is put together: its architecture, security and data model, how it is tested and released, and how to run your own copy. It describes the code, not any running instance.
Architecture
A React single-page app talks to a Node.js and Express REST API, which keeps everything in PostgreSQL through the Sequelize ORM. In production the API also serves the built front end, so there is one application to run.
The same container image runs three services: the web application; a background worker that runs scheduled jobs such as price refreshes and data retention, queued through Redis; and an MCP server through which a compatible AI assistant can read your records and, with your approval, change them.
Optional features are plugins that register their own routes, models and pages, so the core does not depend on them. Runtime configuration lives in the database and is edited from the admin screens; only what the process needs to boot and reach its database comes from the environment.
Security and data model
Signing in sets short-lived, httpOnly session cookies that page scripts cannot read, and every request that changes something carries a CSRF token. Two-factor sign-in with an authenticator app and single sign-on are both supported.
Every record belongs to a user or a household, and access is checked on the server for each request. An account can be shared as its owner, as someone who may add transactions, or read-only.
Secrets the app keeps for you, such as an AI provider key, are encrypted at rest and never shown back in full. AI features send a provider only what the feature needs, a privacy mode can reduce that to symbols or anonymised figures, and your own text is fenced off in prompts so a model reads it as data rather than as instructions.
An assistant connected over MCP uses a scoped personal access token you can revoke, and tools that would change your records wait for your approval. A guest uses a capped demonstration account that is removed automatically once it is left idle.
How it is tested and released
The back end has unit tests and integration tests that run against a real PostgreSQL database, the front end has component tests, and end-to-end tests drive the built app in a real browser.
Guard tests encode the codebase's own rules, for example that every public page has its own metadata or that a request which only reads data never leaves a record behind, and fail the build when one is broken. A guard is not trusted until it has been shown failing on a deliberately planted violation.
Every change runs through continuous integration: linting, the test suites, a coverage floor on the files it changes, a dependency audit, secret and content scans, and a check that the API documentation matches the routes.
Each merge builds one signed container image. It is smoke-tested in a test environment first; promotion to production is a manual step that takes a database backup and rolls back automatically if its checks fail.
Running your own copy
FinanceSight is built to be run by anyone. It needs a container runtime, a PostgreSQL database and a Redis instance; on boot it creates and migrates its own schema, so an upgrade is pulling a newer image.
Instance settings such as integrations, limits and the sign-up policy are managed in the app's admin screens rather than in configuration files. The install guide in the source repository walks through a first setup.
Licence and contributing
The code is licensed under Apache-2.0. Contributions are accepted under the Developer Certificate of Origin: every commit carries a Signed-off-by line rather than a signed agreement.
The source repository is not public yet. This page will link to it when it is.
FinanceSight needs JavaScript to run. See /llms.txt for more.