Security Center

Your financial data deserves the highest level of protection. Learn about the comprehensive security measures we've implemented to keep your information safe and private.

AES-256 Encrypted
SOC 2 Compliant
HTTPS/TLS 1.3

Our Security Promise

We believe that financial privacy is a fundamental right. That's why we've built TrackMyNetWorth with security and privacy as our top priorities from day one.

Zero
Data breaches since inception
256-bit
AES encryption standard
24/7
Security monitoring

How We Protect Your Data

We employ multiple layers of security to ensure your financial information remains safe and private.

End-to-End Encryption

All your data is encrypted using AES-256 encryption, both in transit (HTTPS/TLS 1.3) and at rest. Your financial information is protected with the same level of security used by banks.

Secure Authentication

We use industry-standard authentication with bcrypt password hashing and optional two-factor authentication (2FA) via TOTP apps like Google Authenticator or Authy for an extra layer of security.

Secure Infrastructure

Our infrastructure is hosted on secure, SOC 2 compliant cloud platforms (Supabase & Vercel) with automatic security updates, monitoring, and regular security audits.

Privacy by Design

We never access your personal financial data. No bank connections mean no third-party access to your accounts. Your data stays completely private.

Regular Security Audits

We conduct regular security assessments, vulnerability scans, and penetration testing to ensure our security measures remain effective.

Secure Billing with Stripe

All payment processing is handled through Stripe, a PCI-DSS compliant provider. We never store your credit card details on our servers.

Limited Access

Only essential personnel have access to our systems, and all access is logged and monitored. No employee can access your personal financial data.

Data Protection in Detail

What We Encrypt

  • All financial data (asset values, account names)
  • Personal information (name, email)
  • Notes and custom categories
  • Session data and authentication tokens
  • Database backups and logs

Security Best Practices

  • Regular security updates and patches
  • Automated vulnerability scanning
  • Multi-factor authentication support
  • Secure backup and disaster recovery
  • Incident response procedures

Security Tips for You

Account Security

  • Use a strong, unique password for your account
  • Enable two-factor authentication (2FA) using apps like Google Authenticator, Authy, or 1Password
  • Log out when using shared or public computers

General Safety

  • Never share your login credentials with anyone
  • Regularly review your account for any unusual activity
  • Keep your browser and devices updated

Report Security Issues

If you discover a security vulnerability or have concerns about our security practices, please report it to us immediately. We take all security reports seriously and commit to notifying affected users promptly in the event of any data breach.

For non-security related issues, please use our general contact form. For privacy-related questions, see our Privacy Policy.

Security Center Last Updated: August 6, 2025 | Version: 2.0 | This page is actively maintained and updated with our latest security measures.