Legal
Security Policy
Budget Parent protects financial and household information through layered access, encryption, development, and incident-response practices.
Effective July 29, 2026 · Last updated July 29, 2026
Security program
Budget Parent uses a risk-based security program appropriate for an early-stage financial technology service. Security responsibilities are owned by the CEO and reviewed as the product, team, data flows, and legal obligations change.
Access controls
- Production and sensitive-data access is limited to authorized personnel and service accounts with a business need.
- Role-based access controls and centralized identity providers are used where supported.
- Household ownership is enforced as the application tenancy boundary for budget and financial data.
- Administrative and critical service access should use multi-factor authentication wherever the provider supports it.
- Access is reviewed when responsibilities or service relationships change.
Data protection
- Data is encrypted in transit using TLS 1.2 or better where supported by the service provider.
- Sensitive data is encrypted at rest by managed infrastructure providers, and Plaid access tokens receive additional application-layer encryption.
- Secrets and credentials are kept out of source control and are restricted to the environments and services that require them.
- Production data is not used in public demonstrations.
Development and vulnerability management
- Code changes are reviewed and verified with automated linting, type checks, and production builds as appropriate.
- Dependencies and systems in scope are reviewed or scanned for known vulnerabilities using the tools available for each environment.
- Identified security findings are assessed according to risk and tracked through remediation.
- Third-party services are selected with attention to their security capabilities and access scope.
Incident response
Suspected security incidents are investigated, contained, remediated, and documented. If an incident affects personal information, Budget Parent will notify affected users and regulators when required by applicable law.
Report a vulnerability
To report a suspected vulnerability, email Ali Tooson, CEO, at alitooson@gmail.com with a description, reproduction steps, and the affected location. Do not access, modify, retain, or disclose other users' information, disrupt the service, or use destructive testing. We will acknowledge good-faith reports and coordinate remediation.