Security

Protect the ledger, minimise the credentials.

Spendful’s security model separates authentication, payments and financial records—and never asks for online-banking credentials.

01

Core controls

Managed authentication

Clerk handles sign-in sessions and account authentication flows.

User-scoped access

Protected server operations resolve the authenticated database user before reading or changing records.

Separated payments

Payfast-hosted checkout handles subscription card details outside Spendful.

Structured records

Financial data is stored as account-level records and returned through authenticated routes.

02

What Spendful will not request

  • Your online-banking username or password.
  • A one-time PIN sent by your bank.
  • Your complete card number over email or chat.
  • Remote access to your device to resolve a support request.

03

Your part

Account security is shared work.
  • Use a unique sign-in method and protect the email account connected to Spendful.
  • Review imported statements and remove unnecessary personal information before sharing a sample with support.
  • Sign out on shared devices and remove access if a device is lost.
  • Exported financial data should be encrypted or stored somewhere only you can access.

04

Report a vulnerability

Do not test against another user’s account or access data beyond what is necessary to describe the issue.

Send a private report to security@spendful.com with the affected page, impact and reproducible steps.

Do not include passwords, payment-card data or unredacted financial statements.