Security
Read-only by design
Kepty connects to financial accounts through Plaid with read-only access. Kepty cannot move money, and we never see or store your bank login credentials.
Encryption
- All traffic uses TLS 1.2 or higher.
- Production storage is encrypted at rest, and Plaid access tokens and other sensitive fields are additionally encrypted at the application layer with AES-256-GCM.
- Backups are encrypted and stored separately from production.
Access
- Least-privilege access, granted and reviewed by the founder, revoked within 24 hours of any change.
- Multi-factor authentication on every account that can reach production data.
- Server access by SSH key only. Databases are never exposed to the internet.
Operations
- Daily security updates, weekly dependency scans, and a patch service level of 7 days for critical issues.
- Audit logs for logins, connections and administrative actions, retained for at least 90 days, with alerts for suspicious activity.
- Code changes go through version control, automated tests and approval before deployment.
Incident response
We keep a documented incident response process. If an incident involves data received through Plaid, we notify Plaid within 24 hours of confirming it, and affected customers as required by law.
Your data
- Used only to show you your own numbers. Never sold, never shared with data brokers, never used for advertising.
- Disconnect any account at any time. Delete your workspace and your data is removed within 30 days.
Contact
Security questions and vulnerability reports: security@innovatemore.ai. We acknowledge reports within two business days.