Security

How we protect your data

Data Encryption

All data transmitted between your device and our servers is encrypted using TLS 1.3. Your receipt images and data are encrypted at rest using AES-256 encryption.

Secure Storage

We use Firebase and Google Cloud Storage, which provide enterprise-grade security and compliance with industry standards including SOC 2, ISO 27001, and GDPR.

Authentication

We use Firebase Authentication with secure password hashing and optional two-factor authentication to protect your account.

Access Control

Your data is isolated and only accessible by you. We implement strict access controls and audit logging.

Regular Security Audits

We conduct regular security audits and penetration testing to identify and address potential vulnerabilities.

Compliance

We comply with GDPR, CCPA, and other applicable data protection regulations.

Incident Response

In the event of a security incident, we have procedures in place to quickly identify, contain, and remediate the issue.

Best Practices

We follow industry best practices for secure software development, including regular updates and security patches.