Security & Responsible Disclosure
Security & Responsible Disclosure
> User-facing summary of how we handle security and how to report a vulnerability. The > contributor-facing policy lives in the repository's `SECURITY.md`.
_Last updated: 2026-06-09 · Version 1.0.0_
Reporting a vulnerability
If you believe you have found a security vulnerability, **please report it privately** — do not post it publicly. Email **security@financesight.com** (operators of self-hosted instances: use your own security contact) with a description, steps to reproduce, and the affected version.
We aim to acknowledge reports within 5 working days and to coordinate a disclosure timeline with you. Good-faith research that follows this policy will not be met with legal action; please test only against accounts you control, never access other users' data, and avoid denial-of-service.
How we protect your data
• **Encryption in transit** via TLS, and **encryption at rest** for sensitive secrets (authentication factors, integration keys) using AES-256. - **Strong authentication** — hashed passwords, optional two-factor authentication, and device-level session management you can review and revoke in Settings. - **Least-privilege access control** — your financial data is visible only to you and the people you explicitly share with; administrators cannot see it. - **Audit trails** of security-relevant events on your account.
Recognition
There is no formal bug-bounty programme yet, but we will credit reporters (with permission) once a fix ships.
Contact
Security reports: **security@financesight.com** (or your operator's security contact).
FinanceSight needs JavaScript to run. See /llms.txt for more.