Keeping your account secure.

BudgetR keeps public security statements tied to controls that are already present in the product.

sessions
HTTP-only cookies
passwords
bcrypt hashes
demo
read-only

Authentication

Sign in with a passkey using your device screen lock or security key. Add and manage passkeys in Account security after verifying your email. Passwords remain available for initial account access and are stored as hashes; resetting a password does not remove registered passkeys. You can also review and revoke browser sessions. The account page reports when verification or recovery email delivery is unavailable.

Access control

The server checks current account access and permissions. Administrators have separate privileges and must confirm with a passkey before sensitive changes. Household access is limited to explicitly shared cash accounts and the joint plan; removing a member revokes that shared access.

Abuse protection

Login, registration, and demo endpoints are rate-limited per network address, and demo sessions are blocked from all write operations at the API layer.

External credentials

Plaid handles bank credential collection. BudgetR receives the tokens and account data needed to sync supported accounts.

Security contact

Use the verified contact details below when available. A dedicated security-reporting channel has not been published. Do not include passwords, recovery codes or customer financial records in a report.