Passwordless sign-in
Web sign-in uses time-limited one-time codes and server-side session controls rather than stored account passwords.
BudgetShape contains personal financial information, so access controls and data isolation are treated as core product requirements rather than optional extras.
Web sign-in uses time-limited one-time codes and server-side session controls rather than stored account passwords.
Financial operations are authorised against budget membership on the server. A client-provided budget identifier is not treated as proof of access.
Public production traffic uses HTTPS. The marketing site is designed to be served through CloudFront over modern TLS.
The core product does not need your bank login or a live banking connection to provide recurring-budget functionality.
Production services are designed around least-privilege access and regular backups, with destructive database actions treated as exceptional operations.
If you believe you have found a security issue, contact us privately rather than testing against other users or their data.
security@budgetshape.com →Security is an ongoing process. We do not claim that any internet service is “unhackable” or risk-free. We review controls as the product and attack surface evolve.